CVE-2023-50974

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:appwrite:command_line_interface:*:*:*:*:*:*:*:*

History

12 Jan 2024, 20:25

Type Values Removed Values Added
References () https://appwrite.io/docs/tooling/command-line/installation - () https://appwrite.io/docs/tooling/command-line/installation - Product
References () https://gist.github.com/SkypLabs/72ee00ecfa7d1a3494e2d69a24279c1d - () https://gist.github.com/SkypLabs/72ee00ecfa7d1a3494e2d69a24279c1d - Exploit, Third Party Advisory
First Time Appwrite command Line Interface
Appwrite
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:appwrite:command_line_interface:*:*:*:*:*:*:*:*
CWE CWE-798

09 Jan 2024, 14:01

Type Values Removed Values Added
Summary
  • (es) En Appwrite CLI anterior a 3.0.0, cuando se utiliza el comando de inicio de sesión, las credenciales del usuario de Appwrite se almacenan en un archivo ~/.appwrite/prefs.json con 0644 como permisos UNIX. Cualquier usuario del sistema local puede acceder a esas credenciales.

09 Jan 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 09:15

Updated : 2024-01-12 20:25


NVD link : CVE-2023-50974

Mitre link : CVE-2023-50974

CVE.ORG link : CVE-2023-50974


JSON object : View

Products Affected

appwrite

  • command_line_interface
CWE
CWE-798

Use of Hard-coded Credentials