what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Debezium UI 2.5 Credential Disclosure

Debezium UI 2.5 Credential Disclosure
Posted May 24, 2024
Authored by Ihsan Cetin, Hamza Kaya Toprak

Debezium UI version 2.5 suffers from a credential disclosure vulnerability.

tags | exploit, info disclosure
advisories | CVE-2024-28736
SHA-256 | de2d99cea1ff19deb945b14b659e76d382f5d57f316b7dc8c8aca3034d7435af

Debezium UI 2.5 Credential Disclosure

Change Mirror Download
# Exploit Title: Debezium UI - Credential Leakage

# Google Dork: N/A

# Date: [2024-03-11]

# Exploit Author: Ihsan Cetin, Hamza Kaya Toprak

# Vendor Homepage: https://debezium.io/

# Software Link: N/A

# Version: < 2.5 (REQUIRED)

# Tested on: [N/A]

# CVE : CVE-2024-28736

Proof of concept:

# Details

#Debezium-ui (version 2.5) is vulnerable to a password exposure issue that could allow an attacker to retrieve sensitive credentials in plaintext format.

# PoC :

#Unmasked Password in Connector Configuration: When navigating to the connectors section within the application's connector screen, the password field, which should ideally be masked for security purposes, is briefly displayed in plaintext format during the initial seconds.

# Plaintext Password Retrieval via API Endpoint: By accessing the URL

http://10.0.15.51:8080//api/connectors/1/account-activity/config

#and searching for the database.password parameter, an attacker can retrieve the database password in plaintext format without any authentication.




Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    0 Files
  • 9
    Jul 9th
    0 Files
  • 10
    Jul 10th
    0 Files
  • 11
    Jul 11th
    0 Files
  • 12
    Jul 12th
    0 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close