Логотип exploitDog
bind:CVE-2019-10908
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-10908

Количество 2

Количество 2

nvd логотип

CVE-2019-10908

почти 7 лет назад

In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally. This PRNG has a 48-bit seed that can easily be bruteforced, leading to trivial privilege escalation attacks.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8p8f-c57x-4qw8

больше 3 лет назад

In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally. This PRNG has a 48-bit seed that can easily be bruteforced, leading to trivial privilege escalation attacks.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-10908

In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally. This PRNG has a 48-bit seed that can easily be bruteforced, leading to trivial privilege escalation attacks.

CVSS3: 9.8
0%
Низкий
почти 7 лет назад
github логотип
GHSA-8p8f-c57x-4qw8

In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally. This PRNG has a 48-bit seed that can easily be bruteforced, leading to trivial privilege escalation attacks.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу