Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket.
History

Tue, 10 Dec 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Claris
Claris filemaker Server
Weaknesses CWE-522
CPEs cpe:2.3:a:claris:filemaker_server:*:*:*:*:*:*:*:*
Vendors & Products Claris
Claris filemaker Server
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L'}

cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2024-04-26T15:33:45.536Z

Updated: 2024-08-02T19:37:22.725Z

Reserved: 2023-09-14T19:05:11.476Z

Link: CVE-2023-42955

cve-icon Vulnrichment

Updated: 2024-08-02T19:37:22.725Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T13:46:21.790

Modified: 2024-12-10T17:35:05.937

Link: CVE-2023-42955

cve-icon Redhat

No data.