{"id":"GHSA-vf78-3q9f-92g3","summary":"Hard-coded System User Credentials in Folio Data Export Spring module ","details":"### Impact\nThe module creates a system user that is used to perform internal module-to-module operations.  Credentials for this user are hard-coded in the source code.  This makes it trivial to authenticate as this user, resulting in unauthorized access to potentially dangerous APIs, allowing to view and modify configuration including single-sign-on configuration, to read, add and modify user data, and to read and transfer fees/fines in a patron's account.\n\n### Patches\nUpgrade mod-data-export-spring to \u003e=2.0.2, or a 1.5.x version \u003e=1.5.4.\n\n### Workarounds\nNo known workarounds.\n\n### References\nhttps://wiki.folio.org/x/hbMMBw - FOLIO Security Advisory with Upgrade Instructions\nhttps://github.com/folio-org/mod-data-export-spring/commit/93aff4566bff59e30f4121b5a2bda5b0b508a446 - Fix","aliases":["CVE-2024-23687"],"modified":"2026-07-08T06:29:51.814444883Z","published":"2023-07-25T13:53:42Z","database_specific":{"cwe_ids":["CWE-798"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-07-25T13:53:42Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/folio-org/mod-data-export-spring/security/advisories/GHSA-vf78-3q9f-92g3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23687"},{"type":"WEB","url":"https://github.com/folio-org/mod-data-export-spring/commit/93aff4566bff59e30f4121b5a2bda5b0b508a446"},{"type":"WEB","url":"https://github.com/folio-org/mod-data-export-spring/commit/cb6785565067a2a90c1e2250c241e5b23214c691"},{"type":"PACKAGE","url":"https://github.com/folio-org/mod-data-export-spring"},{"type":"WEB","url":"https://wiki.folio.org/x/hbMMBw"}],"affected":[{"package":{"name":"org.folio:mod-data-export-spring","ecosystem":"Maven","purl":"pkg:maven/org.folio/mod-data-export-spring"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-vf78-3q9f-92g3/GHSA-vf78-3q9f-92g3.json"}},{"package":{"name":"org.folio:mod-data-export-spring","ecosystem":"Maven","purl":"pkg:maven/org.folio/mod-data-export-spring"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-vf78-3q9f-92g3/GHSA-vf78-3q9f-92g3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}