Логотип exploitDog
bind:CVE-2020-26288
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26288

Количество 2

Количество 2

nvd логотип

CVE-2020-26288

около 5 лет назад

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4w46-w44m-3jq3

около 5 лет назад

Parse Server stores password in plain text

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26288

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. It is an npm package "parse-server". In Parse Server before version 4.5.0, user passwords involved in LDAP authentication are stored in cleartext. This is fixed in version 4.5.0 by stripping password after authentication to prevent cleartext password storage.

CVSS3: 7.7
0%
Низкий
около 5 лет назад
github логотип
GHSA-4w46-w44m-3jq3

Parse Server stores password in plain text

CVSS3: 7.7
0%
Низкий
около 5 лет назад

Уязвимостей на страницу