Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mffc-9gx5-99g3

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

python-kerberos vulnerable to KDC spoofing attacks

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

Пакеты

Наименование

kerberos

pip
Затронутые версииВерсия исправления

<= 1.2.5

Отсутствует

Наименование

pykerberos

pip
Затронутые версииВерсия исправления

< 1.1.6

1.1.6

EPSS

Процентиль: 76%
0.00963
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 8 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

redhat
больше 10 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

CVSS3: 8.1
nvd
больше 8 лет назад

The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.

CVSS3: 8.1
debian
больше 8 лет назад

The checkPassword function in python-kerberos does not authenticate th ...

EPSS

Процентиль: 76%
0.00963
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-287