GHSA-rq48-r7v8-mfh6HighCVSS 8.4

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the...

Published
October 3, 2026
Last Modified
October 3, 2026

🔗 CVE IDs covered (1)

📋 Description

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.

🔗 References (4)