CVE-2024-23685
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Jan 19, 2024
Updated: Jan 26, 2024
CWE ID 798
Summary
CVE-2024-23685 is a vulnerability affecting versions of mod-remote-storage below 1.7.2 and between 2.0.0 and 2.0.3. The issue involves hard-coded credentials that provide unauthorized users with read access to sensitive mod-inventory-storage records, including instances, holdings, items, contributor-types, and identifier-types. This vulnerability could potentially lead to data exposure and unintended access, posing a significant risk to affected systems. It is recommended that users upgrade to a secure version of mod-remote-storage to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Open Library Foundation