RPMS Vulnerability?

28 views
Skip to first unread message

Kimball Bighorse

unread,
May 29, 2026, 9:05:31 PM (19 hours ago) May 29
to Hardhats
Hi Sam Habiel and others,

Please consider this potential vulnerability in RPMS:

Once it's properly validated, we will submit to HHS for remediation.

cheers,

Kimball Bighorse
Lakeraven, LLC

Kekoa

unread,
5:21 AM (11 hours ago) 5:21 AM
to Hardhats

Sam Habiel

unread,
8:14 AM (8 hours ago) 8:14 AM
to hard...@googlegroups.com
Looks like a minor issue to me. Somebody encrypting their password before saving on disk. AI classified this as "LOW" severity.

--Sam

--
--
http://groups.google.com/group/Hardhats
To unsubscribe, send email to Hardhats+u...@googlegroups.com

---
You received this message because you are subscribed to the Google Groups "Hardhats" group.
To unsubscribe from this group and stop receiving emails from it, send an email to hardhats+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/hardhats/5b1729be-5696-4b06-a4f2-eaaa366f915en%40googlegroups.com.

Kimball Bighorse

unread,
11:43 AM (4 hours ago) 11:43 AM
to hard...@googlegroups.com
I’d say impact is high but likelihood is low-medium, so low-medium severity would make sense.

Here’s one way we’re considering framing it:

“The vulnerability effectively makes database credentials available to anyone with administrative access to the RPMS application infrastructure.”

Kimball

You received this message because you are subscribed to a topic in the Google Groups "Hardhats" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/hardhats/v4eS0NAEnWs/unsubscribe.
To unsubscribe from this group and all its topics, send an email to hardhats+u...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/hardhats/CABHT961wm3_a39mVjxciB-XUwuYh%3DO2qanySOHcn%3DoJpd0ewpw%40mail.gmail.com.
Reply all
Reply to author
Forward
0 new messages