
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2024-33669 affects Passbolt Browser Extension versions before 4.6.2. The vulnerability involves an information leak where the extension sends multiple requests to HaveIBeenPwned while a password is being typed (NVD, Quarkslab Blog).
The vulnerability occurs when the Passbolt Browser Extension sends queries to the HaveIBeenPwned API as soon as a user types a password, with a 300ms delay between keystrokes. For passwords longer than 7 characters, each keystroke triggers an API query containing the first 5 nibbles (20 bits) of the SHA1 hash of the current password. This implementation allows an attacker observing the HTTPS queries to potentially brute force the password being typed (Quarkslab Blog).
An attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API can more easily brute force passwords that are manually typed by the user. The vulnerability becomes particularly effective for passwords of 11 characters or longer, where multiple sequential API queries can be used to progressively determine each character (NVD, Quarkslab Blog).
The vulnerability has been fixed in Passbolt Browser Extension version 4.6.2. The fix involves only querying the Pwned Passwords API when saving a new or updated password, and only if the password's estimated entropy is larger than 60 bits (Passbolt Incident, Quarkslab Blog).
Following the disclosure, Troy Hunt updated the Pwned Passwords APIv3 documentation to include a warning about the risks of incremental searches. The vulnerability was responsibly disclosed to Passbolt, who responded promptly and collaborated actively to ensure a smooth resolution (Quarkslab Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”