CVE-2023-50974

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:appwrite:command_line_interface:*:*:*:*:*:*:*:*

History

12 Jan 2024, 20:25

Type Values Removed Values Added
References () https://appwrite.io/docs/tooling/command-line/installation - () https://appwrite.io/docs/tooling/command-line/installation - Product
References () https://gist.github.com/SkypLabs/72ee00ecfa7d1a3494e2d69a24279c1d - () https://gist.github.com/SkypLabs/72ee00ecfa7d1a3494e2d69a24279c1d - Exploit, Third Party Advisory
CPE cpe:2.3:a:appwrite:command_line_interface:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-798
First Time Appwrite
Appwrite command Line Interface

09 Jan 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 09:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-50974

Mitre link : CVE-2023-50974

CVE.ORG link : CVE-2023-50974


JSON object : View

Products Affected

appwrite

  • command_line_interface
CWE
CWE-798

Use of Hard-coded Credentials