CVE-2023-34240 – Weak passwords allowed in cloudexplorer-lite
https://notcve.org/view.php?id=CVE-2023-34240
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not enforce strong passwords. This vulnerability has been fixed in version 1.2.0. • https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-px4m-5j22-5mw4 • CWE-521: Weak Password Requirements •
CVE-2023-3423 – Weak Password Requirements in cloudexplorer-dev/cloudexplorer-lite
https://notcve.org/view.php?id=CVE-2023-3423
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0. • https://github.com/cloudexplorer-dev/cloudexplorer-lite/commit/7d4dab60352079953b7be120afe9bd14983ae3bc https://huntr.dev/bounties/dd19c7d0-70f1-4d86-a552-611dfa8e0139 • CWE-521: Weak Password Requirements •
CVE-2023-2845 – Improper Access Control in cloudexplorer-dev/cloudexplorer-lite
https://notcve.org/view.php?id=CVE-2023-2845
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. • https://github.com/cloudexplorer-dev/cloudexplorer-lite/commit/d9f55a44e579d312977b02317b2020de758b763a https://huntr.dev/bounties/ac10e81c-998e-4425-9d74-b985d9b0254c • CWE-284: Improper Access Control •
CVE-2023-2844 – Authorization Bypass Through User-Controlled Key in cloudexplorer-dev/cloudexplorer-lite
https://notcve.org/view.php?id=CVE-2023-2844
Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. • https://github.com/cloudexplorer-dev/cloudexplorer-lite/commit/d9f55a44e579d312977b02317b2020de758b763a https://huntr.dev/bounties/6644b36e-603d-4dbe-8ee2-5df8b8fb2e22 • CWE-639: Authorization Bypass Through User-Controlled Key •