CVE-2023-50974

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:appwrite:command_line_interface:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-01-09 09:15

Updated : 2024-01-12 20:25


NVD link : CVE-2023-50974

Mitre link : CVE-2023-50974

CVE.ORG link : CVE-2023-50974


JSON object : View

Products Affected

appwrite

  • command_line_interface
CWE
CWE-798

Use of Hard-coded Credentials