An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.
History

Wed, 18 Jun 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Passbolt passbolt Browser Extension
CPEs cpe:2.3:a:passbolt:passbolt_browser_extension:*:*:*:*:*:*:*:*
Vendors & Products Passbolt passbolt Browser Extension

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-04-26T00:00:00

Updated: 2024-08-02T02:36:04.567Z

Reserved: 2024-04-26T00:00:00

Link: CVE-2024-33669

cve-icon Vulnrichment

Updated: 2024-04-29T12:12:35.925Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-26T01:15:46.383

Modified: 2025-06-18T19:26:21.547

Link: CVE-2024-33669

cve-icon Redhat

No data.