Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3h7-3c45-qj4v

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.8
CVSS3: 7.5

Описание

Python Keyring does not securely initialize encryption cipher

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

Пакеты

Наименование

keyring

pip
Затронутые версииВерсия исправления

<= 0.9.1

0.9.2

EPSS

Процентиль: 20%
0.00065
Низкий

8.8 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-326

Связанные уязвимости

ubuntu
около 13 лет назад

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

redhat
больше 13 лет назад

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

nvd
около 13 лет назад

Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.

debian
около 13 лет назад

Python Keyring 0.9.1 does not securely initialize the cipher when encr ...

EPSS

Процентиль: 20%
0.00065
Низкий

8.8 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-326