Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-13421

Опубликовано: 23 авг. 2019
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10openshift-elasticsearch-pluginFix deferred
Red Hat OpenShift Container Platform 3.11openshift3/ose-logging-elasticsearch5Fix deferred
Red Hat OpenShift Container Platform 3.9openshift-elasticsearch-pluginFix deferred
Red Hat OpenShift Container Platform 3.9search-guard-2Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-logging-elasticsearch5Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1747476search-guard: Administrative user is able to retrieve bcrypt password hashes of other users

EPSS

Процентиль: 59%
0.00388
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

CVSS3: 4.9
github
больше 3 лет назад

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

EPSS

Процентиль: 59%
0.00388
Низкий

4.9 Medium

CVSS3