Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-627p-vx8v-8v2c

Опубликовано: 19 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6

Описание

Use of a Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerability in Beta80 Life 1st allows an Attacker to Bruteforce User Passwords or find a collision to gain access to a target application using BETA80 “Life 1st Identity Manager” as a service for authentication.This issue affects Life 1st: 1.5.2.14234.

Use of a Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerability in Beta80 Life 1st allows an Attacker to Bruteforce User Passwords or find a collision to gain access to a target application using BETA80 “Life 1st Identity Manager” as a service for authentication.This issue affects Life 1st: 1.5.2.14234.

EPSS

Процентиль: 5%
0.00021
Низкий

6 Medium

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 6
nvd
11 месяцев назад

Broken or Risky Cryptographic Algorithm, Use of Password Hash With Insufficient Computational Effort, Use of Weak Hash, Use of a One-Way Hash with a Predictable Salt vulnerabilities in Beta80 "Life 1st Identity Manager" enable an attacker with access to password hashes to bruteforce user passwords or find a collision to ultimately while attempting to gain access to a target application that uses "Life 1st Identity Manager" as a service for authentication. This issue affects Life 1st: 1.5.2.14234.

EPSS

Процентиль: 5%
0.00021
Низкий

6 Medium

CVSS3

Дефекты

CWE-327