Executive brief
Buttercup is a popular password manager application that stores encrypted credentials. A vulnerability allows attackers to obtain the hash of the master password by accessing the /vaults.json/ file, which stores encrypted credentials including the master password. This could enable attackers to mount offline brute-force attacks against the master password, potentially compromising all stored passwords if the master password is weak.
Technical details
The vulnerability (CWE-916: Use of Password Hash With Insufficient Computational Effort) stems from Buttercup storing the encrypted master password at rest in the /vaults.json/ file. An attacker with local file access can retrieve this file and obtain the password hash. The vulnerability requires local file system access to the stored vault data, making it a local attack vector. An attacker can then perform offline brute-force attacks against the master password without rate limiting. The issue was fixed in version 2.20.3 and later patched in version 7.4.0.
Affected products
- Buttercup buttercup up to 2.20.3
Timeline
- 2023-09-08: disclosed
- 2023-09-15: other: Issue opened on GitHub with refactoring requirement to remove master password from storage