Lucene search

K
vulnrichmentAppleVULNRICHMENT:CVE-2023-42955
HistoryApr 26, 2024 - 3:33 p.m.

CVE-2023-42955

2024-04-2615:33:45
apple
github.com
2
claris international
password exposure
admin console
administrator role
node.js socket

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*"
    ],
    "vendor": "claris",
    "product": "filemaker_server",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "20.3.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.8

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2023-42955