High-severity #vulnerability in #Passwordstate #credential manager. #Patch now .
#security #highseverity #privacy
High-severity #vulnerability in #Passwordstate #credential manager. #Patch now .
#security #highseverity #privacy
Passwordstate, a key tool for thousands of organizations, now faces a critical flaw that lets attackers bypass MFA with a clever URL trick. Could your sensitive data be at risk? Read on to learn why immediate updates might be a must.
#passwordstate
#cybersecurity
#vulnerability
#infosec
#authenticationbypass
Funny that the topic seems to be Password Managers. This was one that I was asked to address on my day off.
It's bananas to me that the BrowserExtension API is just always on and cannot be shut off. Token authorization is flawed during it's checks and then you can dump literally everything 😅
Happy Holidays!
https://www.modzero.com/static/MZ-22-03_Passwordstate_Security_Disclosure_Report-v1.0.pdf
#security #passwordmanager #PasswordState #cve #vulnerability #API
Angreifer könnten Sicherheitslücken im Passwortmanager Passwordstate kombinieren
Passwordstate kommt vornehmlich in Firmen zur Kennwortverwaltung zum Einsatz. Angreifer könnten Passwörter im Klartext auslesen. Ein Update ist verfügbar.
#Passwordstate #Passwörter #Patch #Security #Sicherheitslücken #Update