CVE-2024-23685: Openlibraryfoundation Mod-Remote-Storage

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.

Affected products

  • Openlibraryfoundation Mod-Remote-Storage: before 1.7.2 (fixed in 1.7.2); from 2.0.0, before 2.0.3 (fixed in 2.0.3)

Published 2024-01-19. Last modified 2026-07-14.