Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-25qj-gfr4-9mhj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 19 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

redhat
почти 20 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

CVSS3: 5.5
nvd
больше 19 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

CVSS3: 5.5
debian
больше 19 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which mak ...

EPSS

Процентиль: 14%
0.00045
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-916