CVE-2023-34097
CVE-2023-34097 affects Hoppscotch, an open-source API development ecosystem, in versions prior to 2023.4.5. The vulnerability involves the exposure of the database password in system logs when the database connection string is displayed. This is a high-severity vulnerability (CVSS 8.8) with a low attack complexity, allowing authenticated attackers with log access to achieve full database access and privilege escalation. There are no known exploits, Metasploit modules, or public exploit code available, and it currently lacks significant community discussion or media coverage.
Impacted Technologies
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023.4.5CPE matchmatch criteria | cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:* |
CVSS Data
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploit Intelligence
Social Chatter
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
Media Mentions
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.