Логотип exploitDog
bind:CVE-2020-1940
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-1940

Количество 2

Количество 2

nvd логотип

CVE-2020-1940

почти 6 лет назад

The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute to the credentials object but does not remove it upon processing during the first phase of the authentication. In combination with additional, independent authentication mechanisms, this may lead to the new password being disclosed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h68-wvv6-8r5h

около 4 лет назад

Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-1940

The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute to the credentials object but does not remove it upon processing during the first phase of the authentication. In combination with additional, independent authentication mechanisms, this may lead to the new password being disclosed.

CVSS3: 7.5
1%
Низкий
почти 6 лет назад
github логотип
GHSA-3h68-wvv6-8r5h

Improper Removal of Sensitive Information Before Storage or Transfer in Apache Jackrabbit Oak

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу