PT-2019-16097 · Nim+1 · Http Authentication Library+1

Publicado

2019-12-30

·

Atualizado

2021-07-21

·

CVE-2019-20138

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HTTP Authentication library for Nim versions prior to 2019-12-27
Description The issue is related to weak password hashing. The default algorithm for libsodium's crypto pwhash str is not used in the affected versions.
Recommendations For versions prior to 2019-12-27, update the HTTP Authentication library to use the default algorithm for libsodium's crypto pwhash str to strengthen password hashing.

Correção

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-20138

Produtos afetados

Http Authentication Library
Libsodium