PT-2026-106186 · Ghost · Ghost
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ghost versions 0.7.2 through 6.63.x
Description
Staff-level users can determine the relative ordering of hashed passwords belonging to other staff users. This issue does not directly disclose the password hashes or provide a practical method for password recovery.
Recommendations
Update to version 6.64.0.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ghost