CVE-2023-50974

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
09/01/2024
Last modified:
12/01/2024

Description

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:appwrite:command_line_interface:*:*:*:*:*:*:*:* 3.0.0 (excluding)