CVE-2024-23687

CRITICAL

Openlibraryfoundation Mod-data-export-spring - Hard-coded Credentials

Title source: rule
STIX 2.1

Description

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations including single-sign-on, and manipulate fees/fines.

Scores

CVSS v3 9.1
EPSS 0.0054
EPSS Percentile 67.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (2)
openlibraryfoundation/mod-data-export-spring < 1.5.4
org.folio/mod-data-export-spring 2.0.0 - 2.0.2Maven
Published Jan 19, 2024
Tracked Since Feb 18, 2026