Описание
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
Ссылки
- Patch
- PatchVendor Advisory
- Patch
- Patch
- Patch
- Patch
- Patch
- PatchVendor Advisory
- Patch
- Patch
- Patch
- Patch
Уязвимые конфигурации
Одно из
Одно из
EPSS
5 Medium
CVSS2
Дефекты
Связанные уязвимости
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entr ...
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
EPSS
5 Medium
CVSS2