CVE-2024-33669
Last modified
CVE-2024-33669 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Passbolt | Passbolt Browser Extension | < 4.6.2 |
References
- https://blog.quarkslab.com/passbolt-a-bold-use-of-haveibeenpwned.htmlExploit, Third Party Advisory
- https://haveibeenpwned.comProduct
- https://help.passbolt.com/incidents/pwned-password-service-information-leakIssue Tracking, Vendor Advisory
- https://www.passbolt.comProduct
- https://blog.quarkslab.com/passbolt-a-bold-use-of-haveibeenpwned.htmlExploit, Third Party Advisory
- https://haveibeenpwned.comProduct
- https://help.passbolt.com/incidents/pwned-password-service-information-leakIssue Tracking, Vendor Advisory
- https://www.passbolt.comProduct
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-33669?
How severe is CVE-2024-33669?
How do I fix CVE-2024-33669?
Are you affected by CVE-2024-33669?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
