Описание
Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.
Ссылки
- Third Party Advisory
- Release NotesVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 19 (включая) до 30 (исключая)
cpe:2.3:a:atlassian:agiloft:*:*:*:*:*:*:*:*
EPSS
Процентиль: 11%
0.00038
Низкий
7.5 High
CVSS3
Дефекты
CWE-1392
Связанные уязвимости
CVSS3: 7.5
github
5 месяцев назад
Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.
EPSS
Процентиль: 11%
0.00038
Низкий
7.5 High
CVSS3
Дефекты
CWE-1392