CVE-2023-52723

In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.
Configurations

No configuration.

History

21 Nov 2024, 08:40

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/04/30/1 - () http://www.openwall.com/lists/oss-security/2024/04/30/1 -
References () https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1 - () https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1 -
References () https://invent.kde.org/pim/libksieve/-/tags/v23.03.80 - () https://invent.kde.org/pim/libksieve/-/tags/v23.03.80 -
References () https://lists.debian.org/debian-lts-announce/2024/05/msg00004.html - () https://lists.debian.org/debian-lts-announce/2024/05/msg00004.html -
References () https://www.openwall.com/lists/oss-security/2024/04/25/1 - () https://www.openwall.com/lists/oss-security/2024/04/25/1 -

03 Jul 2024, 01:43

Type Values Removed Values Added
CWE CWE-798
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1

05 May 2024, 22:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/05/msg00004.html -

01 May 2024, 17:15

Type Values Removed Values Added
Summary
  • (es) En KDE libksieve anterior al 23.03.80, kmanagesieve/session.cpp coloca una contraseña de texto plano en los registros del servidor porque a una variable de nombre de usuario se le asigna accidentalmente un valor de contraseña.
References
  • () http://www.openwall.com/lists/oss-security/2024/04/30/1 -

29 Apr 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-29 06:15

Updated : 2024-11-21 08:40


NVD link : CVE-2023-52723

Mitre link : CVE-2023-52723

CVE.ORG link : CVE-2023-52723


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials