Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38m3-mrrg-hx5g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality.

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality.

EPSS

Процентиль: 59%
0.00377
Низкий

8.1 High

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 8.1
nvd
больше 6 лет назад

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. In lib/OA/Dal/PasswordRecovery.php, the function generateRecoveryId() generates a password reset token that relies on the PHP uniqid function and consequently depends only on the current server time, which is often visible in an HTTP Date header.

EPSS

Процентиль: 59%
0.00377
Низкий

8.1 High

CVSS3

Дефекты

CWE-338