PT-2023-24204 · Highlight · Highlight

Vadman97

·

Publicado

2023-05-26

·

Atualizado

2023-06-05

·

CVE-2023-33187

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Highlight versions prior to 6.0.0
Description Highlight may record passwords on customer deployments when a password html input is switched to type="text" via a javascript "Show Password" button. This issue arises because the expected behavior of always obfuscating type="password" inputs is not followed when the input type is changed. As a result, customers may unintentionally have their password values recorded when using a "Show Password" button, assuming that switching to type="text" would also prevent recording of the input.
Recommendations For versions prior to 6.0.0, upgrade to version 6.0.0 to ensure that inputs which used to be type="password" continue to be obfuscated even when their type is changed. As a temporary workaround, consider adding the highlight-mask css-class obfuscation to the affected parts of the DOM to prevent unintentional recording of password values.

Exploit

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-36943
CVE-2023-33187
GHSA-9QPJ-QQ2R-5MCC

Produtos afetados

Highlight