CVE-2023-33187 affects Highlight, an open-source full-stack monitoring platform, where it could unintentionally record passwords. The vulnerability arises when a "Show Password" button changes an HTML input from type="password" to type="text", causing Highlight to record the input despite expected obfuscation. Rated Medium severity with a CVSS score of 6.5, this issue has a network attack vector and high confidentiality impact, allowing an authenticated attacker to potentially access sensitive user data. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability. The issue was patched in Highlight version 6.0.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.0CPE matchmatch criteria | cpe:2.3:a:highlight:highlight:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.