Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v94f-h6hr-hfqh

Опубликовано: 09 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an unauthenticated remote attacker to efficiently brute force passwords in specific situations.

A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an unauthenticated remote attacker to efficiently brute force passwords in specific situations.

EPSS

Процентиль: 81%
0.01554
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an unauthenticated remote attacker to efficiently brute force passwords in specific situations.

EPSS

Процентиль: 81%
0.01554
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307