PT-2024-20074 · Darkhttpd · Darkhttpd

Matthias Gerstner

·

Published

2024-01-21

·

Updated

2026-03-29

·

CVE-2024-23770

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions darkhttpd versions 1.15 and earlier
Description The issue allows local users to discover credentials by listing processes and their arguments. This is related to the --auth option.
Recommendations For darkhttpd versions 1.15 and earlier, consider restricting access to process listings to minimize the risk of credential discovery until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2024-23770

Affected Products

Darkhttpd