Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mvr-wqp8-rqpq

Опубликовано: 25 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.

EPSS

Процентиль: 48%
0.00245
Низкий

7.5 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash using a timing attack.

EPSS

Процентиль: 48%
0.00245
Низкий

7.5 High

CVSS3

Дефекты

CWE-269