PT-2023-21983 · Pimcore · Pimcore/Customer-Data-Framework

Published

2023-05-25

·

Updated

2023-05-31

·

CVE-2023-2881

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions pimcore/customer-data-framework versions prior to 3.3.10
Description The issue concerns storing passwords in a recoverable format. An attacker can exploit this by enumerating passwords for specific IDs, potentially leading to the disclosure of password hashes that can be cracked using tools like hashcat.
Recommendations For versions prior to 3.3.10, update to version 3.3.10 to resolve the issue. As a temporary workaround, apply the patch manually from https://github.com/pimcore/customer-data-framework/commit/d1d58c10313f080737dc1e71fab3beb12488a1e6.patch to mitigate the risk.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-2881
GHSA-J65R-G7Q2-F8V3

Affected Products

Pimcore/Customer-Data-Framework