Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rg9r-f32f-755r

Опубликовано: 02 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.

An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.

EPSS

Процентиль: 59%
0.00374
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-338
CWE-640

Связанные уязвимости

CVSS3: 8.8
nvd
около 3 лет назад

An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.

EPSS

Процентиль: 59%
0.00374
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-338
CWE-640