Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9970

Опубликовано: 20 фев. 2017
Источник: redhat
CVSS3: 5.1

Описание

jasypt before 1.9.2 allows a timing attack against the password hash comparison.

A vulnerability was found in Jasypt that would allow an attacker to perform a timing attack on password hash comparison.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6jasyptNot affected
Red Hat JBoss BRMS 5jasyptWill not fix
Red Hat JBoss Data Grid 7jasyptAffected
Red Hat JBoss Fuse 6jasyptNot affected
Red Hat JBoss Fuse Service Works 6jasyptWill not fix
Red Hat OpenShift Enterprise 2jasyptUnder investigation
Red Hat Data Grid 7.1.2FixedRHSA-2018:029412.02.2018
Red Hat JBoss BPMS 6.4jasyptFixedRHSA-2017:254629.08.2017
Red Hat JBoss BRMS 6.4jasyptFixedRHSA-2017:254729.08.2017
Red Hat JBoss EAP 7FixedRHSA-2017:281026.09.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1455566jasypt: Vulnerable to timing attack against the password hash comparison

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

jasypt before 1.9.2 allows a timing attack against the password hash comparison.

CVSS3: 7.5
nvd
больше 9 лет назад

jasypt before 1.9.2 allows a timing attack against the password hash comparison.

CVSS3: 7.5
debian
больше 9 лет назад

jasypt before 1.9.2 allows a timing attack against the password hash c ...

CVSS3: 7.5
github
больше 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Jasypt

5.1 Medium

CVSS3