Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6pf-6px3-6h92

Опубликовано: 01 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

EPSS

Процентиль: 17%
0.00266
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 9.9
nvd
2 дня назад

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

EPSS

Процентиль: 17%
0.00266
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-338