Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5507

Опубликовано: 06 нояб. 2012
Источник: redhat
CVSS2: 1.8

Описание

AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.

Отчет

Not vulnerable. This issue did not affect the versions of luci (as provided by conga) as shipped with Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5congaNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=874110(Plone): Timing attack in password validation

1.8 Low

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.

debian
больше 11 лет назад

AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone ...

CVSS3: 7.5
github
больше 7 лет назад

Plone and Zope2 affected by Race Condition

1.8 Low

CVSS2