Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1940

Опубликовано: 28 янв. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute to the credentials object but does not remove it upon processing during the first phase of the authentication. In combination with additional, independent authentication mechanisms, this may lead to the new password being disclosed.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:jackrabbit_oak:*:*:*:*:*:*:*:*
Версия от 1.2.0 (включая) до 1.22.0 (включая)

EPSS

Процентиль: 71%
0.0069
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-212

Связанные уязвимости

CVSS3: 7.5
github
около 4 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak

EPSS

Процентиль: 71%
0.0069
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-212