Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-8796

Опубликовано: 17 сент. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes.

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needed

esm-apps/focal

released

3.1.0-2ubuntu0.1~esm1
esm-apps/jammy

released

4.0.0-2ubuntu0.1~esm1
esm-apps/noble

not-affected

esm-apps/xenial

ignored

end of ESM support, was needed
focal

ignored

end of standard support, was needed
jammy

needed

noble

not-affected

oracular

not-affected

Показывать по

EPSS

Процентиль: 49%
0.00641
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
почти 2 года назад

Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes.

CVSS3: 5.3
debian
почти 2 года назад

Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & ...

CVSS3: 5.3
github
почти 2 года назад

Devise-Two-Factor Authentication Uses Insufficient Default OTP Shared Secret Length

EPSS

Процентиль: 49%
0.00641
Низкий

5.3 Medium

CVSS3