SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2022-10-03T16:21:02
Updated: 2022-10-03T16:21:02
Reserved: 2022-10-03T00:00:00
Link: CVE-2010-5079
JSON object: View
NVD Information
Status : Analyzed
Published: 2012-09-17T17:55:02.750
Modified: 2012-09-18T04:00:00.000
Link: CVE-2010-5079
JSON object: View
Redhat Information
No data.
CWE