Описание
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.
Ссылки
- Third Party Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.12.0 (включая) до 1.12.12 (включая)Версия от 1.13.0 (включая) до 1.13.3 (включая)
Одно из
cpe:2.3:a:sos-berlin:jobscheduler:*:*:*:*:*:*:*:*
cpe:2.3:a:sos-berlin:jobscheduler:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04538
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-330
Связанные уязвимости
github
больше 3 лет назад
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.
EPSS
Процентиль: 89%
0.04538
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-330