Описание
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Quickstart Cloud Installer 1 | Distribution | Out of support scope |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=1370315QCI: uses MD5 as password hash algorithm on deployed systems
1.9 Low
CVSS3
1.2 Low
CVSS2
Связанные уязвимости
CVSS3: 8.4
nvd
почти 10 лет назад
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
CVSS3: 8.4
github
больше 4 лет назад
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
1.9 Low
CVSS3
1.2 Low
CVSS2