Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.143445
Kategorie:Web application abuses
Titel:OpenCast < 8.1.0 Password Hashing Vulnerability
Zusammenfassung:OpenCast is prone to an insecure password hashing vulnerability.
Beschreibung:Summary:
OpenCast is prone to an insecure password hashing vulnerability.

Vulnerability Insight:
User passwords are stored in the database using the rather outdated and
cryptographically insecure MD5 hash algorithm. Furthermore, the hashes are salted using the username instead of
a random salt, causing hashes for users with the same username and password to collide which is problematic
especially for popular users like the default admin user.

This essentially means that for an attacker, it might be feasible to reconstruct a user's password given access
to these hashes.

Note that attackers needing access to the hashes means that they must gain access to the database in which these
are stored first to be able to start cracking the passwords.

Affected Software/OS:
OpenCast versions prior to 8.1.0.

Solution:
Update to version 8.1.0 or later. Note, that old hashes remain MD5 until the
password is updated.

CVSS Score:
5.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-5229
https://github.com/opencast/opencast/commit/32bfbe5f78e214e2d589f92050228b91d704758e
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.