Junglewise Threat Intelligence

CVE-2023-41646: Buttercup password manager plaintext master password storage

CVE-2023-41646 · Severity: low · CVSS 3.1 · Published 2023-09-08

Vendors: npm.

Executive brief

Buttercup is a popular password manager application that stores encrypted credentials. A vulnerability allows attackers to obtain the hash of the master password by accessing the /vaults.json/ file, which stores encrypted credentials including the master password. This could enable attackers to mount offline brute-force attacks against the master password, potentially compromising all stored passwords if the master password is weak.

Technical details

The vulnerability (CWE-916: Use of Password Hash With Insufficient Computational Effort) stems from Buttercup storing the encrypted master password at rest in the /vaults.json/ file. An attacker with local file access can retrieve this file and obtain the password hash. The vulnerability requires local file system access to the stored vault data, making it a local attack vector. An attacker can then perform offline brute-force attacks against the master password without rate limiting. The issue was fixed in version 2.20.3 and later patched in version 7.4.0.

Affected products

  • Buttercup buttercup up to 2.20.3

Timeline

  • 2023-09-08: disclosed
  • 2023-09-15: other: Issue opened on GitHub with refactoring requirement to remove master password from storage

References