PT-2019-16097 · Nim+1 · Http Authentication Library+1

Published

2019-12-30

·

Updated

2021-07-21

·

CVE-2019-20138

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HTTP Authentication library for Nim versions prior to 2019-12-27
Description The issue is related to weak password hashing. The default algorithm for libsodium's crypto pwhash str is not used in the affected versions.
Recommendations For versions prior to 2019-12-27, update the HTTP Authentication library to use the default algorithm for libsodium's crypto pwhash str to strengthen password hashing.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20138

Affected Products

Http Authentication Library
Libsodium