Description
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.
Published: 2024-01-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hv5g-q4h3-64q4 Hard-coded credentials in org.folio:mod-remote-storage
Github GHSA Github GHSA GHSA-m8v7-469p-5x89 Hard-coded System User Credentials in Folio Data Export Spring module
History

Sat, 29 Nov 2025 02:00:00 +0000

Type Values Removed Values Added
Description Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types. Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.

Fri, 30 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Openlibraryfoundation Mod-remote-storage
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-29T01:28:17.705Z

Reserved: 2024-01-19T17:35:09.985Z

Link: CVE-2024-23685

cve-icon Vulnrichment

Updated: 2024-08-01T23:06:25.360Z

cve-icon NVD

Status : Modified

Published: 2024-01-19T21:15:10.470

Modified: 2025-11-29T02:15:51.837

Link: CVE-2024-23685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses