PT-2023-32949 · Folio · Mod-Data-Export-Spring

Published

2023-07-25

·

Updated

2025-11-29

·

CVE-2024-23687

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FOLIO mod-data-export-spring versions before 1.5.4 FOLIO mod-data-export-spring versions from 2.0.0 to 2.0.2
Description The issue concerns hard-coded credentials in the mod-data-export-spring module, allowing unauthenticated users to access critical APIs. This results in unauthorized access to potentially dangerous APIs, enabling the modification of user data, configurations including single-sign-on, and the manipulation of fees/fines in a patron's account. The module creates a system user for internal operations, and the hard-coded credentials for this user make it easy to authenticate and gain unauthorized access.
Recommendations For FOLIO mod-data-export-spring versions before 1.5.4, upgrade to version 1.5.4 or later. For FOLIO mod-data-export-spring versions from 2.0.0 to 2.0.2, upgrade to version 2.0.2 or later.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-23687
GHSA-9RHQ-86FM-QXQC
GHSA-VF78-3Q9F-92G3

Affected Products

Mod-Data-Export-Spring