Vulnerabilities/

Buttercup allows attackers to obtain the hash of the master password

Severity:
Medium

Description

Buttercup allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/.

This affects the Buttercup app up to version 2.20.3.

Recommendation

Update the buttercup package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
buttercup
Anything's wrong? Let us know Last updated on December 13, 2023

This issue is available in SmartScanner Professional

See Pricing