5

CVE-2012-3798

The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bryce HamrickJanrain Capture Version6.x-1.0
   DrupalDrupal Version-
Bryce HamrickJanrain Capture Version7.x-1.0
   DrupalDrupal Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.52% 0.712
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://drupal.org/node/1632702
Patch
http://drupal.org/node/1632704
Patch
http://drupal.org/node/1632734
Patch
Vendor Advisory
http://osvdb.org/82957