{"id":"CVE-2024-23685","aliases":["GHSA-m8v7-469p-5x89"],"url":"https://o3.security/vulnerability/CVE-2024-23685","summary":"FOLIO mod-remote-storage Hard Coded Credentials","details":"### Impact\nThe module creates a system user that is used to perform internal module-to-module operations.  Credentials for this user are hard-coded in the source code.  This makes it trivial to authenticate as this user, allowing unauthorized read access to these mod-inventory-storage records: instances, holdings, items, contributor-types, identifier-types. This includes records marked as suppressed from discovery.\n\n### Patches\nUpgrade mod-remote-storage to >=2.0.3, or a 1.7.x version >=1.7.1.\n\n### Workarounds\nNo known workarounds.\n\n### References\nhttps://wiki.folio.org/x/hbMMBw - FOLIO Security Advisory with Upgrade Instructions\nhttps://github.com/folio-org/mod-remote-storage/commit/57df495f76e9aa5be9ce7ce3a65f89b6dbcbc13b - Fix","published":"2024-01-19T21:07:13.048Z","modified":"2026-08-12T03:51:24.517394394Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.folio:mod-remote-storage","fixedVersion":"2.0.3"},{"ecosystem":"Maven","name":"org.folio:mod-remote-storage","fixedVersion":"1.7.2"}],"fix":{"url":"https://github.com/folio-org/mod-remote-storage/commit/57df495f76e9aa5be9ce7ce3a65f89b6dbcbc13b","label":"folio-org/mod-remote-storage@57df495"},"references":[{"type":"WEB","url":"https://repo.maven.apache.org/maven2"},{"type":"WEB","url":"https://wiki.folio.org/x/hbMMBw"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/23xxx/CVE-2024-23685.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m8v7-469p-5x89"},{"type":"ADVISORY","url":"https://github.com/folio-org/mod-remote-storage/security/advisories/GHSA-m8v7-469p-5x89"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23685"},{"type":"ADVISORY","url":"https://vulncheck.com/advisories/vc-advisory-GHSA-m8v7-469p-5x89"},{"type":"FIX","url":"https://github.com/folio-org/mod-remote-storage/commit/57df495f76e9aa5be9ce7ce3a65f89b6dbcbc13b"},{"type":"PACKAGE","url":"https://github.com/folio-org/mod-remote-storage"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.517394394Z"}}