Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r838-q6jp-58xx

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Improper Restriction of Excessive Authentication Attempts in py-bcrypt

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

Пакеты

Наименование

py-bcrypt

pip
Затронутые версииВерсия исправления

< 0.3

0.3

EPSS

Процентиль: 51%
0.00279
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

CVSS3: 7.5
nvd
около 6 лет назад

The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

CVSS3: 7.5
debian
около 6 лет назад

The py-bcrypt module before 0.3 for Python does not properly handle co ...

EPSS

Процентиль: 51%
0.00279
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-307