GHSA-7cwq-p8cr-h9qg

Suggest an improvement
Source
https://github.com/advisories/GHSA-7cwq-p8cr-h9qg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-7cwq-p8cr-h9qg/GHSA-7cwq-p8cr-h9qg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7cwq-p8cr-h9qg
Aliases
Published
2023-09-08T00:31:02Z
Modified
2023-12-13T23:41:32Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Buttercup allows attackers to obtain the hash of the master password
Details

Buttercup allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/.

This affects the Buttercup app up to version 2.20.3.

Database specific
{
    "cwe_ids":  [
        "CWE-916"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-12-13T23:22:06Z",
    "nvd_published_at":  "2023-09-07T22:15:07Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / buttercup

Package

Affected ranges

Type
SEMVER
Events
Introduced
2.20.3
Fixed
7.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-7cwq-p8cr-h9qg/GHSA-7cwq-p8cr-h9qg.json"