CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be used to send a request with that user's authority. This issue has been addressed in version 1.0.0-beta.8. Users are advised to upgrade. Users unable to upgrade should disable logging for successful login attempts by the configuration files.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2984 CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be used to send a request with that user's authority. This issue has been addressed in version 1.0.0-beta.8. Users are advised to upgrade. Users unable to upgrade should disable logging for successful login attempts by the configuration files.
Github GHSA Github GHSA GHSA-j72f-h752-mx4w Insertion of Sensitive Information into Log
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T21:37:54.644Z

Reserved: 2023-11-17T19:43:37.554Z

Link: CVE-2023-48708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-24T18:15:07.520

Modified: 2024-11-21T08:32:18.263

Link: CVE-2023-48708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses