{"id":"GHSA-v427-c49j-8w6x","summary":"Cleartext Storage of Sensitive Information in HMAC SHA256 Authentication","details":"### Impact\n**secretKey**, an important key for HMAC SHA256 authentication, was stored in the database in raw form.\n\nIf a malicious person somehow had access to the data in the database, they could use the key and secretKey for HMAC SHA256 authentication to send requests impersonating that person.\n\n### Patches\nUpgrade to Shield v1.0.0-beta.8 or later.\n\nAfter upgrading, all existing secret keys must be encrypted.\nSee https://github.com/codeigniter4/shield/blob/develop/UPGRADING.md for details.\n\n### Workarounds\nNone.\n\n### References\n- https://codeigniter4.github.io/shield/references/authentication/hmac/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue or discussion in [codeigniter4/shield](https://github.com/codeigniter4/shield)\n* Email us at [security@codeigniter.com](mailto:security@codeigniter.com)\n","aliases":["CVE-2023-48707"],"modified":"2026-09-10T03:49:59.131615068Z","published":"2023-11-23T00:28:14Z","database_specific":{"nvd_published_at":"2023-11-24T18:15:07Z","cwe_ids":["CWE-312"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-11-23T00:28:14Z"},"references":[{"type":"WEB","url":"https://github.com/codeigniter4/shield/security/advisories/GHSA-v427-c49j-8w6x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-48707"},{"type":"WEB","url":"https://github.com/codeigniter4/shield/commit/f77c6ae20275ac1245330a2b9a523bf7e6f6202f"},{"type":"PACKAGE","url":"https://github.com/codeigniter4/shield"}],"affected":[{"package":{"name":"codeigniter4/shield","ecosystem":"Packagist","purl":"pkg:composer/codeigniter4/shield"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0-beta.8"}]}],"versions":["v1.0.0-beta","v1.0.0-beta.2","v1.0.0-beta.3","v1.0.0-beta.4","v1.0.0-beta.5","v1.0.0-beta.6","v1.0.0-beta.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-v427-c49j-8w6x/GHSA-v427-c49j-8w6x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N"}]}