In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Kaspersky

Published: 2021-01-19T16:53:36

Updated: 2021-01-19T16:53:36

Reserved: 2020-12-31T00:00:00


Link: CVE-2020-35929

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-01-19T17:15:12.957

Modified: 2021-01-29T14:25:33.700


Link: CVE-2020-35929

JSON object: View

cve-icon Redhat Information

No data.

CWE