Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j5v3-363p-g843

Опубликовано: 20 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

OpenCRX vulnerable to password enumeration via error messages in password reset

OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

Пакеты

Наименование

org.opencrx:opencrx-client

maven
Затронутые версииВерсия исправления

< 5.2.2

5.2.2

EPSS

Процентиль: 44%
0.0022
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attacker to determine if a username, email or ID is valid.

EPSS

Процентиль: 44%
0.0022
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203