AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2014-09-30T14:00:00

Updated: 2014-09-30T12:57:01

Reserved: 2012-10-24T00:00:00


Link: CVE-2012-5507

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-09-30T14:55:06.953

Modified: 2014-10-02T18:25:06.290


Link: CVE-2012-5507

JSON object: View

cve-icon Redhat Information

No data.

CWE