Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xhv-qc2f-6267

Опубликовано: 29 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.5

Описание

NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.

NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.

EPSS

Процентиль: 9%
0.00032
Низкий

3.5 Low

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 3.5
nvd
больше 1 года назад

NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.

EPSS

Процентиль: 9%
0.00032
Низкий

3.5 Low

CVSS3

Дефекты

CWE-312