5

CVE-2010-5079

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SilverstripeSilverstripe Version2.3.0
SilverstripeSilverstripe Version2.3.1
SilverstripeSilverstripe Version2.3.2
SilverstripeSilverstripe Version2.3.3
SilverstripeSilverstripe Version2.3.4
SilverstripeSilverstripe Version2.3.5
SilverstripeSilverstripe Version2.3.6
SilverstripeSilverstripe Version2.3.7
SilverstripeSilverstripe Version2.3.8
SilverstripeSilverstripe Version2.3.9
SilverstripeSilverstripe Version2.4.0
SilverstripeSilverstripe Version2.4.1
SilverstripeSilverstripe Version2.4.2
SilverstripeSilverstripe Version2.4.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.88% 0.767
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2012/04/30/3
http://www.openwall.com/lists/oss-security/2011/01/03/12
http://www.openwall.com/lists/oss-security/2012/04/30/1
http://www.openwall.com/lists/oss-security/2012/05/01/3
http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4
Patch
Vendor Advisory
http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10
Patch
http://open.silverstripe.org/changeset/114497
http://open.silverstripe.org/changeset/114498
Patch
http://open.silverstripe.org/changeset/114503
Patch
http://open.silverstripe.org/changeset/114504
Patch
http://open.silverstripe.org/changeset/114505
Patch