Описание
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
Ссылки
- Release Notes
- Vendor Advisory
- ExploitThird Party Advisory
- Release Notes
- Vendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 23.1 (исключая)
cpe:2.3:a:search-guard:search_guard:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00388
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-522
CWE-200
Связанные уязвимости
CVSS3: 4.9
redhat
больше 6 лет назад
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
CVSS3: 4.9
github
больше 3 лет назад
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
EPSS
Процентиль: 59%
0.00388
Низкий
4.9 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-522
CWE-200