In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
References
Link | Resource |
---|---|
https://appwrite.io/docs/tooling/command-line/installation | Product |
https://gist.github.com/SkypLabs/72ee00ecfa7d1a3494e2d69a24279c1d | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2024-01-09T00:00:00
Updated: 2024-01-09T08:36:25.462934
Reserved: 2023-12-17T00:00:00
Link: CVE-2023-50974
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-09T09:15:42.480
Modified: 2024-01-12T20:25:04.120
Link: CVE-2023-50974
JSON object: View
Redhat Information
No data.
CWE