{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-23685", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2024-01-19T17:35:09.985Z", "datePublished": "2024-01-19T21:07:13.048Z", "dateUpdated": "2026-07-14T22:54:45.414Z" }, "containers": { "cna": { "affected": [ { "collectionURL": "https://repo.maven.apache.org/maven2", "defaultStatus": "unaffected", "packageURL": "pkg:maven/org.folio/mod-remote-storage", "packageName": "org.folio:mod-remote-storage", "versions": [ { "lessThan": "1.7.2", "status": "affected", "version": "0", "versionType": "maven" }, { "lessThan": "2.0.3", "status": "affected", "version": "2.0.0", "versionType": "maven" } ] } ], "cpeApplicability": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:openlibraryfoundation:mod-remote-storage:*:*:*:*:*:*:*:*", "versionEndExcluding": "1.7.2", "versionStartIncluding": "0", "vulnerable": true }, { "criteria": "cpe:2.3:a:openlibraryfoundation:mod-remote-storage:*:*:*:*:*:*:*:*", "versionEndExcluding": "2.0.3", "versionStartIncluding": "2.0.0", "vulnerable": true } ], "negate": false, "operator": "OR" } ], "operator": "OR" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.