Buttercup allows attackers to obtain the hash of the master password
Moderate severity
GitHub Reviewed
Published
Sep 8, 2023
to the GitHub Advisory Database
•
Updated Dec 13, 2023
Description
Published by the National Vulnerability Database
Sep 7, 2023
Published to the GitHub Advisory Database
Sep 8, 2023
Reviewed
Dec 13, 2023
Last updated
Dec 13, 2023
Buttercup allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/.
This affects the Buttercup app up to version 2.20.3.
References