Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9970

Опубликовано: 20 фев. 2017
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

jasypt before 1.9.2 allows a timing attack against the password hash comparison.

A vulnerability was found in Jasypt that would allow an attacker to perform a timing attack on password hash comparison.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6jasyptNot affected
Red Hat JBoss BRMS 5jasyptWill not fix
Red Hat JBoss Fuse 6jasyptNot affected
Red Hat JBoss Fuse Service Works 6jasyptWill not fix
Red Hat OpenShift Enterprise 2jasyptUnder investigation
Red Hat Data Grid 7.1.2jasyptFixedRHSA-2018:029412.02.2018
Red Hat JBoss BPMS 6.4jasyptFixedRHSA-2017:254629.08.2017
Red Hat JBoss BRMS 6.4jasyptFixedRHSA-2017:254729.08.2017
Red Hat JBoss EAP 7FixedRHSA-2017:281026.09.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-artemis-nativeFixedRHSA-2017:280926.09.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1455566jasypt: Vulnerable to timing attack against the password hash comparison

EPSS

Процентиль: 76%
0.00944
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

jasypt before 1.9.2 allows a timing attack against the password hash comparison.

CVSS3: 7.5
nvd
больше 8 лет назад

jasypt before 1.9.2 allows a timing attack against the password hash comparison.

CVSS3: 7.5
debian
больше 8 лет назад

jasypt before 1.9.2 allows a timing attack against the password hash c ...

CVSS3: 7.5
github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Jasypt

EPSS

Процентиль: 76%
0.00944
Низкий

5.1 Medium

CVSS3