CWE
532
Advisory Published
CVE Published
Updated

CVE-2023-48708: Insertion of Sensitive Information into Log in codeigniter4/shield

First published: Thu Nov 23 2023(Updated: )

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be used to send a request with that user's authority. This issue has been addressed in version 1.0.0-beta.8. Users are advised to upgrade. Users unable to upgrade should disable logging for successful login attempts by the configuration files.

Credit: security-advisories@github.com security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
composer/codeigniter4/shield<1.0.0-beta.8
1.0.0-beta.8
CodeIgniter Shield=1.0.0-beta
CodeIgniter Shield=1.0.0-beta2
CodeIgniter Shield=1.0.0-beta3
CodeIgniter Shield=1.0.0-beta4
CodeIgniter Shield=1.0.0-beta5
CodeIgniter Shield=1.0.0-beta6
CodeIgniter Shield=1.0.0-beta7

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the impact of CVE-2023-48708?

    If successful login attempts are recorded, the raw tokens are stored in the log table and can be obtained by a malicious person, allowing them to send requests with the user's authority.

  • How can a malicious person obtain raw tokens from the log table?

    If a malicious person somehow views the data in the log table, they can obtain a raw token.

  • What can a malicious person do with a raw token obtained from the log table?

    A malicious person can use a raw token to send requests with the authority of the user associated with that token.

  • What version of codeigniter4/shield is affected by CVE-2023-48708?

    The vulnerability affects codeigniter4/shield version 1.0.0-beta.8 exclusively.

  • Where can I find more information about codeigniter4/shield and fixing this vulnerability?

    You can find more information about codeigniter4/shield and how to fix this vulnerability in the references provided: https://github.com/codeigniter4/shield/security/advisories/GHSA-j72f-h752-mx4w, https://github.com/codeigniter4/shield/commit/7e84c3fb3411294f70890819bfe51781bb9dc8e4, https://codeigniter4.github.io/shield/getting_started/authenticators/

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203