Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8c5-7mvv-crq3

Опубликовано: 18 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.

Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.

EPSS

Процентиль: 26%
0.0009
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

Insecure storage of LDAP passwords in the authentication functionality of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allows members (with read access to the application database) to decrypt the LDAP passwords of users who successfully authenticate to web management via LDAP.

EPSS

Процентиль: 26%
0.0009
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-922