Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjcx-2qxv-xf7v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url "/bdswebui/assignusers/".

EPSS

Процентиль: 37%
0.00158
Низкий

Дефекты

CWE-522