PT-2024-25426 · Passbolt · Passbolt Browser Extension

Ruben Meeuwissen

·

Published

2024-04-26

·

Updated

2025-06-18

·

CVE-2024-33669

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Passbolt Browser Extension versions prior to 4.6.2
Description An issue in the Passbolt Browser Extension results in an information leak. As a user types a password, multiple requests are sent to HaveIBeenPwned, allowing an attacker who can observe these HTTPS queries to the Pwned Password API to more easily brute force manually typed passwords.
Recommendations For versions prior to 4.6.2, update to version 4.6.2 or later to resolve the issue. As a temporary workaround, consider disabling the password checking feature that sends requests to HaveIBeenPwned until a patch is applied. Restrict access to sensitive information and use additional security measures to protect against brute force attacks.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-33669
GHSA-XFQ4-78J7-V594

Affected Products

Passbolt Browser Extension