All incidents

Autofill Suggestions

Bug Bounty: Autofill suggestions logic flaw

Summary

Product affected:Passbolt browser extension
Version affected:v2.11.1 and below.
Version fixed:v2.11.2
Affected component:  Autofill suggestions
Vulnerability Type:Business Logic Errors (CWE-840)
CVSS Score:6.2 (Medium)

Description

Impact of issue

Fix

Event timeline

  • 2019-11-17: Security researcher notifies passbolt team about the issue.
  • 2019-11-17: Passbolt acknowledges the issue and start working on a fix.
  • 2019-11-20: Fix is ready and included as part of v2.11.2 release UAT.
  • 2019-11-21: Passbolt publishes a fix.

Current status:

Last updated: 2019-12-06 11:00:00 CET
Flag of European UnionMade in Europe. Privacy by default.
Passbolt Security Incident Report: vulnerability - November 26th, 2019