PT-2023-31575 · Unknown+1 · Faye-Websocket.Js+1

Kelsey Tian

·

Publicado

2023-12-21

·

Atualizado

2023-12-29

·

CVE-2023-50475

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions bcoin versions 2.2.0
Description An issue was discovered that allows remote attackers to obtain sensitive information via weak hashing algorithms in the component vendorfaye-websocket.js. This issue affects the bsock component.
Recommendations For version 2.2.0, consider disabling the use of weak hashing algorithms in the vendorfaye-websocket.js component until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-50475
GHSA-JJ93-39PF-7MCF

Produtos afetados

Bcoin
Faye-Websocket.Js