Openlibraryfoundation maintains a small portfolio of library management and data-handling modules, including data export and remote storage components, with a durable weakness pattern centered on hard-coded credential exposure. This represents a focused attack surface characteristic of backend infrastructure tools where credential management lapses carry direct access implications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openlibraryfoundation over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23687CRITICAL Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify | Jan 19, 2024 | 9.1 | 26 | NO | NO |
CVE-2024-23685MEDIUM Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including i | Jan 19, 2024 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openlibraryfoundation.
Media articles that mention a CVE ID that affects a product developed by Openlibraryfoundation — matched by CVE ID, not by vendor name.