HIGH🇵🇱 Wersja polska

CVE-2023-34097

CVSS 7.8v3.1pub. 2023-06-05upd. 2024-11-21

hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the database connection string. Attackers with access to read system logs will be able to elevate privilege with full access to the database. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Hoppscotch

    APP
    Hoppscotch
    < 2023.4.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-50160CRITICAL10.0PL ✓same product

Hoppscotch: mass assignment w endpoincie onboardingu umożliwia przejęcie serwera

CVE-2026-28215CRITICAL9.1PL ✓same product

Hoppscotch — Auth Bypass umożliwia przejęcie konfiguracji instancji

CVE-2026-34932HIGH8.5same product

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulne...

CVE-2026-34931HIGH8.5same product

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect v...

CVE-2026-28216HIGH8.3same product

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read...