NewPass before 1.2.0 stores passwords (rather than...
Low severity
Unreviewed
Published
Jun 29, 2024
to the GitHub Advisory Database
•
Updated Nov 25, 2024
Description
Published by the National Vulnerability Database
Jun 29, 2024
Published to the GitHub Advisory Database
Jun 29, 2024
Last updated
Nov 25, 2024
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.
References