关键信息总结 Title: NutzBoot project NutzBoot NutzBoot 2.6.0-SNAPSHOT Information Disclosure (Wallet password leakage) Description: The Web3j demo module exposes /web3j/local/accounts without authentication and serializes the Web3jAccount object, including the password property. This allows remote callers to retrieve cleartext passphrases for Ethereum accounts. Source: GitHub link User: sh7err03 (UID 92418) Submission Date: 11/10/2025 11:04 AM (24 days ago) Moderation Date: 11/30/2025 03:13 PM (20 days later) Status: Accepted VulDB Entry: 333814 [nutzam NutzBoot up to 2.6.0-SNAPSHOT Ethereum Wallet EthModule.java information disclosure] Points: 17