Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v537-cf87-935c

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

EPSS

Процентиль: 21%
0.00069
Низкий

8.4 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.4
ubuntu
почти 6 лет назад

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

redhat
больше 12 лет назад

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

CVSS3: 8.4
nvd
почти 6 лет назад

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

CVSS3: 8.4
debian
почти 6 лет назад

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste ...

EPSS

Процентиль: 21%
0.00069
Низкий

8.4 High

CVSS3

Дефекты

CWE-287