5
CVE-2012-3798
- EPSS 1.52%
- Veröffentlicht 27.06.2012 00:55:06
- Zuletzt bearbeitet 16.06.2026 23:43:54
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bryce Hamrick ≫ Janrain Capture Version6.x-1.0
Bryce Hamrick ≫ Janrain Capture Version7.x-1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.52% | 0.712 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://drupal.org/node/1632702
http://drupal.org/node/1632704
http://drupal.org/node/1632734
http://osvdb.org/82957