PT-2023-21983 · Pimcore · Pimcore/Customer-Data-Framework
Published
2023-05-25
·
Updated
2023-05-31
·
CVE-2023-2881
CVSS v3.1
6.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
pimcore/customer-data-framework versions prior to 3.3.10
Description
The issue concerns storing passwords in a recoverable format. An attacker can exploit this by enumerating passwords for specific IDs, potentially leading to the disclosure of password hashes that can be cracked using tools like hashcat.
Recommendations
For versions prior to 3.3.10, update to version 3.3.10 to resolve the issue.
As a temporary workaround, apply the patch manually from https://github.com/pimcore/customer-data-framework/commit/d1d58c10313f080737dc1e71fab3beb12488a1e6.patch to mitigate the risk.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pimcore/Customer-Data-Framework