Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-528v-fv7h-v892

Опубликовано: 29 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack. This issue does not impact Person documents created through user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html .

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack. This issue does not impact Person documents created through user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html .

EPSS

Процентиль: 48%
0.00249
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.9
nvd
почти 2 года назад

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® Administrator are secured using a cryptographically weak hash algorithm. This could enable attackers with access to the hashed value to determine a user's password, e.g. using a brute force attack. This issue does not impact Person documents created through user registration https://help.hcltechsw.com/domino/10.0.1/admin/conf_userregistration_c.html .

EPSS

Процентиль: 48%
0.00249
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-306