Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qqv-r2q4-jxhm

Опубликовано: 14 янв. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

privacyIDEA Improper Input Validation vulnerability

privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http request with user=&pass= to /validate/check url. This vulnerability appears to have been fixed in 2.23.2.

Пакеты

Наименование

privacyIDEA

pip
Затронутые версииВерсия исправления

< 2.23.2

2.23.2

EPSS

Процентиль: 56%
0.00334
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http request with user=<space>&pass= to /validate/check url. This vulnerability appears to have been fixed in 2.23.2.

EPSS

Процентиль: 56%
0.00334
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20