Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m97-xc46-rw9w

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

phpMyAdmin Unsafe comparison of XSRF/CSRF token

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.

Пакеты

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.0, < 4.0.10.13

4.0.10.13

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.4, < 4.4.15.3

4.4.15.3

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.5, < 4.5.4

4.5.4

EPSS

Процентиль: 76%
0.00994
Низкий

7.5 High

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.

CVSS3: 7.5
nvd
больше 9 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.

CVSS3: 7.5
debian
больше 9 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x b ...

suse-cvrf
больше 9 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 76%
0.00994
Низкий

7.5 High

CVSS3

Дефекты

CWE-203