Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvfv-5h6h-r46w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

EPSS

Процентиль: 59%
0.00388
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 4.9
redhat
больше 6 лет назад

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

CVSS3: 4.9
nvd
больше 6 лет назад

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

EPSS

Процентиль: 59%
0.00388
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-200
CWE-522