CVE-2023-50294

Plaintext Display of Secret Access Key in GROWI App Settings (/admin/app)

GROWI のアプリ設定 (/admin/app) における Secret access key の平文表示

In GROWI v6.0.6 and earlier versions, authentication credentials for external services in the Admin App Settings are transmitted from the server to the client without being masked.

Disclosure Date

2023/12/13

Credit

azara (@a_zara_n)

Reference