5
CVE-2012-3798
- EPSS 1.52%
- Veröffentlicht 27.06.2012 00:55:06
- Zuletzt bearbeitet 16.06.2026 23:43:54
- Erkennungen
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bryce Hamrick ≫ Janrain Capture Version 6.x-1.0
Bryce Hamrick ≫ Janrain Capture Version 7.x-1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.52% | 0.712 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://drupal.org/node/1632702
http://drupal.org/node/1632704
http://drupal.org/node/1632734
http://osvdb.org/82957