6.5

CVE-2023-48707

Cleartext Storage of Sensitive Information in codeigniter4/shield

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a malicious person somehow had access to the data in the database, they could use the key and secretKey for HMAC SHA256 authentication to send requests impersonating that corresponding user. This issue has been addressed in version 1.0.0-beta.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Codeigniter ≫ Shield Version 1.0.0 Update beta
Codeigniter ≫ Shield Version 1.0.0 Update beta2
Codeigniter ≫ Shield Version 1.0.0 Update beta3
Codeigniter ≫ Shield Version 1.0.0 Update beta4
Codeigniter ≫ Shield Version 1.0.0 Update beta5
Codeigniter ≫ Shield Version 1.0.0 Update beta6
Codeigniter ≫ Shield Version 1.0.0 Update beta7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.198
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
security-advisories@github.com 5 0.7 4.2
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

https://github.com/codeigniter4/shield/commit/f77c6ae20275ac1245330a2b9a523bf7e6f6202f
Patch
https://github.com/codeigniter4/shield/security/advisories/GHSA-v427-c49j-8w6x
Vendor Advisory