CVE-2010-5079
MEDIUM severity · CVSS 5 · CWE-310
5CVSS MEDIUM
Summary
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)2%
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10 ↗
Additional information
- NVD record
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10Patch
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4Patch
- http://open.silverstripe.org/changeset/114498Patch
- http://open.silverstripe.org/changeset/114503Patch
- http://open.silverstripe.org/changeset/114504Patch
- http://open.silverstripe.org/changeset/114505Patch
- http://open.silverstripe.org/changeset/114497
- http://www.openwall.com/lists/oss-security/2011/01/03/12