Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rpcg-4hqj-wfv3

Опубликовано: 03 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.4

Описание

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, and can then decrypt the stored credentials of any specific installation to which the attacker separately obtains the encrypted configuration file.

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-321

8.6 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-321