Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7fh-9pv8-fwc2

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

EPSS

Процентиль: 51%
0.00275
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 7 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

CVSS3: 5.3
nvd
почти 7 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

CVSS3: 5.3
debian
почти 7 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks wh ...

EPSS

Процентиль: 51%
0.00275
Низкий

7.5 High

CVSS3

Дефекты

CWE-287