Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-24553

Опубликовано: 24 июн. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*:*
Версия от 3.14.0 (включая) до 3.15.0 (включая)

EPSS

Процентиль: 17%
0.00056
Низкий

7.5 High

CVSS3

Дефекты

CWE-916

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

EPSS

Процентиль: 17%
0.00056
Низкий

7.5 High

CVSS3

Дефекты

CWE-916