Description
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak.
Recommendation
Update the passbolt-browser-extension package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.6.2
- Patched version(s): 4.6.2
References
- GHSA-xfq4-78j7-v594
- blog.quarkslab.com
- haveibeenpwned.com
- www.passbolt.com
- CVE-2024-33669
- CWE-200
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- Strapi may leak sensitive user information, user reset password, tokens via content-manager views - @strapi/utils - CVE-2023-36472
- Strapi may leak sensitive user information, user reset password, tokens via content-manager views - CVE-2023-36472
- sanitize-html Information Exposure vulnerability - CVE-2024-21501
- Generation of Error Message Containing Sensitive Information in zsa - CVE-2024-37162
You might also like:
- Tags:
- npm
- passbolt-browser-extension
Anything's wrong? Let us know Last updated on June 19, 2025


