CVE-2023-34097 affects Hoppscotch, an open-source API development ecosystem, in versions prior to 2023.4.5. The vulnerability involves the exposure of the database password in system logs when the database connection string is displayed. This is a high-severity vulnerability (CVSS 8.8) with a low attack complexity, allowing authenticated attackers with log access to achieve full database access and privilege escalation. There are no known exploits, Metasploit modules, or public exploit code available, and it currently lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023.4.5CPE matchmatch criteria | cpe:2.3:a:hoppscotch:hoppscotch:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.