In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://gist.github.com/SkypLabs/72ee00ecfa7d1a3494e2d69a24279c1d | third party advisory exploit |
https://appwrite.io/docs/tooling/command-line/installation | product |