Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxm3-2c37-cc6h

Опубликовано: 24 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.9
CVSS3: 7.5

Описание

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

EPSS

Процентиль: 17%
0.00056
Низкий

5.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

EPSS

Процентиль: 17%
0.00056
Низкий

5.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-916