Описание
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.112 (исключая)
cpe:2.3:a:ajenti:ajenti_plugin_core:*:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00329
Низкий
7.5 High
CVSS3
Дефекты
CWE-287
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
debian
4 месяца назад
ajenti.plugin.core defines all necessary core elements to allow Ajenti ...
CVSS3: 7.5
github
4 месяца назад
ajenti.plugin.core has password bypass when 2FA is activated
EPSS
Процентиль: 26%
0.00329
Низкий
7.5 High
CVSS3
Дефекты
CWE-287
NVD-CWE-noinfo