PT-2023-21983 · Pimcore · Pimcore/Customer-Data-Framework

CVE-2023-2881

·

Publicado

2023-05-25

·

Atualizado

2023-05-31

CVSS v3.1

6.7

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions pimcore/customer-data-framework versions prior to 3.3.10
Description The issue concerns storing passwords in a recoverable format. An attacker can exploit this by enumerating passwords for specific IDs, potentially leading to the disclosure of password hashes that can be cracked using tools like hashcat.
Recommendations For versions prior to 3.3.10, update to version 3.3.10 to resolve the issue. As a temporary workaround, apply the patch manually from https://github.com/pimcore/customer-data-framework/commit/d1d58c10313f080737dc1e71fab3beb12488a1e6.patch to mitigate the risk.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2881
GHSA-J65R-G7Q2-F8V3

Produtos afetados

Pimcore/Customer-Data-Framework