Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmxw-5jh4-p3j8

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be able to trivially bruteforce offline the passwords of associated users.

Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be able to trivially bruteforce offline the passwords of associated users.

EPSS

Процентиль: 37%
0.00161
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 9.8
nvd
почти 7 лет назад

Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be able to trivially bruteforce offline the passwords of associated users.

EPSS

Процентиль: 37%
0.00161
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-326