Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f78q-jqxf-66cm

Опубликовано: 26 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

EPSS

Процентиль: 21%
0.00069
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-307

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

EPSS

Процентиль: 21%
0.00069
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-307