Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xg2-vjm8-8r9m

Опубликовано: 12 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.

A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.

EPSS

Процентиль: 31%
0.00121
Низкий

8.1 High

CVSS3

Дефекты

CWE-1390

Связанные уязвимости

CVSS3: 8.1
nvd
12 месяцев назад

A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.

EPSS

Процентиль: 31%
0.00121
Низкий

8.1 High

CVSS3

Дефекты

CWE-1390