PT-2019-16097 · Nim+1 · Http Authentication Library+1
Published
2019-12-30
·
Updated
2021-07-21
·
CVE-2019-20138
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HTTP Authentication library for Nim versions prior to 2019-12-27
Description
The issue is related to weak password hashing. The default algorithm for libsodium's crypto pwhash str is not used in the affected versions.
Recommendations
For versions prior to 2019-12-27, update the HTTP Authentication library to use the default algorithm for libsodium's crypto pwhash str to strengthen password hashing.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Http Authentication Library
Libsodium