PT-2021-19234 · Unknown · Open-Audit

Vsevolod Shamov

·

Published

2021-01-20

·

Updated

2022-07-12

·

CVE-2021-3130

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open-AudIT versions up to 3.5.3
Description The issue concerns the web interface of Open-AudIT, where sensitive information such as SSH secrets, Windows passwords, and SNMP strings are hidden from users using HTML 'password field' obfuscation. However, an attacker can use Developer tools or similar methods to modify this obfuscation, making the credentials visible.
Recommendations For Open-AudIT versions up to 3.5.3, update to a version later than 3.5.3 to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of credential exposure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-3130

Affected Products

Open-Audit