CVE-2024-33669
Passbolt Browser Extension leaks password information
6.1
MEDIUM
CVSS 3.1
EPSS 0.21%
Description
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.
How to fix CVE-2024-33669
To remediate CVE-2024-33669, upgrade the affected package to a fixed version below.
- —upgrade to 4.6.2 or later
Is CVE-2024-33669 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4.6.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N |