Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9r4-9w2c-2xcp

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.

The default algorithm is HMAC-SHA1, which should only be used for legacy systems.

These versions default to using 1000 iterations.

Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.

The default algorithm is HMAC-SHA1, which should only be used for legacy systems.

These versions default to using 1000 iterations.

Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.

EPSS

Процентиль: 13%
0.00226
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.

CVSS3: 5.3
nvd
около 2 месяцев назад

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.

CVSS3: 5.3
debian
около 2 месяцев назад

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default al ...

EPSS

Процентиль: 13%
0.00226
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-916