Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Passbolt: a bold use of HaveIBeenPwned

Summary

Quarkslab shows Passbolt's use of the Pwned Passwords API leaked the passwords it checked: an observer of API queries could recover an 11+ character password via incremental search; fixed in v4.6.2.
Published
Collected

original ↗

Related coverage

back