In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.
References
Configurations
No configuration.
History
21 Nov 2024, 08:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2024/04/30/1 - | |
References | () https://invent.kde.org/pim/libksieve/-/commit/6b460ba93ac4ac503ba039d0b788ac7595120db1 - | |
References | () https://invent.kde.org/pim/libksieve/-/tags/v23.03.80 - | |
References | () https://lists.debian.org/debian-lts-announce/2024/05/msg00004.html - | |
References | () https://www.openwall.com/lists/oss-security/2024/04/25/1 - |
03 Jul 2024, 01:43
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-798 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
05 May 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 May 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
29 Apr 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-29 06:15
Updated : 2024-11-21 08:40
NVD link : CVE-2023-52723
Mitre link : CVE-2023-52723
CVE.ORG link : CVE-2023-52723
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials