VYPR

Passbolt Browser Extension

by Passbolt

CVEs (1)

  • CVE-2024-33669MedApr 26, 2024
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password…