Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9rhq-86fm-qxqc | Hard-coded credentials in org.folio:mod-data-export-spring |
Github GHSA |
GHSA-vf78-3q9f-92g3 | Hard-coded System User Credentials in Folio Data Export Spring module |
Sat, 29 Nov 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate fees/fines. | Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate fees/fines. |
Wed, 13 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-29T02:01:15.356Z
Reserved: 2024-01-19T17:35:09.985Z
Link: CVE-2024-23687
Updated: 2024-08-01T23:06:25.426Z
Status : Modified
Published: 2024-01-19T22:15:08.517
Modified: 2025-11-29T03:15:56.533
Link: CVE-2024-23687
No data.
OpenCVE Enrichment
No data.
Github GHSA