Описание
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
Уязвимые конфигурации
Конфигурация 1Версия до 5.12.5 (исключая)
cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00135
Низкий
2 Low
CVSS3
2.6 Low
CVSS3
Дефекты
CWE-308
Связанные уязвимости
CVSS3: 2
ubuntu
5 месяцев назад
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
CVSS3: 2
debian
5 месяцев назад
SOGo before 5.12.5 does not renew the OTP if a user disables/enables i ...
CVSS3: 2
github
5 месяцев назад
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
EPSS
Процентиль: 3%
0.00135
Низкий
2 Low
CVSS3
2.6 Low
CVSS3
Дефекты
CWE-308