CVE-2023-50974: Medium severity appwrite vulnerability
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50974?
CVE-2023-50974 has been classified as a medium severity vulnerability due to its potential for unauthorized credential access.
How do I fix CVE-2023-50974?
To fix CVE-2023-50974, update the Appwrite CLI to version 3.0.0 or higher.
What does CVE-2023-50974 affect?
CVE-2023-50974 affects the Appwrite CLI versions prior to 3.0.0, where user credentials are stored with insecure permissions.
What are the risks associated with CVE-2023-50974?
The risks of CVE-2023-50974 include exposure of sensitive user credentials to other local system users.
How can I verify if I am affected by CVE-2023-50974?
To verify if you are affected by CVE-2023-50974, check your Appwrite CLI version to see if it is below 3.0.0.