PT-2021-19234 · Unknown · Open-Audit
Vsevolod Shamov
·
Published
2021-01-20
·
Updated
2022-07-12
·
CVE-2021-3130
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open-AudIT versions up to 3.5.3
Description
The issue concerns the web interface of Open-AudIT, where sensitive information such as SSH secrets, Windows passwords, and SNMP strings are hidden from users using HTML 'password field' obfuscation. However, an attacker can use Developer tools or similar methods to modify this obfuscation, making the credentials visible.
Recommendations
For Open-AudIT versions up to 3.5.3, update to a version later than 3.5.3 to resolve the issue. As a temporary workaround, consider restricting access to the web interface to minimize the risk of credential exposure.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open-Audit