PT-2019-16097 · Nim+1 · Http Authentication Library+1
Publicado
2019-12-30
·
Atualizado
2021-07-21
·
CVE-2019-20138
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HTTP Authentication library for Nim versions prior to 2019-12-27
Description
The issue is related to weak password hashing. The default algorithm for libsodium's crypto pwhash str is not used in the affected versions.
Recommendations
For versions prior to 2019-12-27, update the HTTP Authentication library to use the default algorithm for libsodium's crypto pwhash str to strengthen password hashing.
Correção
Use of a Broken Cryptographic Algorithm
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Http Authentication Library
Libsodium