CVE-2024-34525

FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:lanol:filecodebox:2.0:*:*:*:*:*:*:*

History

25 Nov 2025, 19:48

Type Values Removed Values Added
References () https://github.com/vastsa/FileCodeBox/issues/133 - () https://github.com/vastsa/FileCodeBox/issues/133 - Exploit, Issue Tracking
First Time Lanol filecodebox
Lanol
CPE cpe:2.3:a:lanol:filecodebox:2.0:*:*:*:*:*:*:*

21 Nov 2024, 09:18

Type Values Removed Values Added
References () https://github.com/vastsa/FileCodeBox/issues/133 - () https://github.com/vastsa/FileCodeBox/issues/133 -

03 Jul 2024, 02:00

Type Values Removed Values Added
Summary
  • (es) FileCodeBox 2.0 almacena una contraseña de OneDrive y una clave de AWS en un archivo env de texto sin cifrar.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-591

06 May 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-06 00:15

Updated : 2025-11-25 19:48


NVD link : CVE-2024-34525

Mitre link : CVE-2024-34525

CVE.ORG link : CVE-2024-34525


JSON object : View

Products Affected

lanol

  • filecodebox
CWE
CWE-591

Sensitive Data Storage in Improperly Locked Memory