PT-2024-32464 · Dozzle+1 · Dozzle+1

Mohammed90

·

Published

2024-09-27

·

Updated

2024-11-05

·

CVE-2024-47182

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dozzle versions prior to 8.5.3
Description The issue concerns the use of an insecure hash for passwords. Specifically, the app uses sha-256, which is susceptible to rainbow table attacks due to its design as a fast message digest hash. This leaves users vulnerable. The app switches to bcrypt, a more secure hash for passwords, in version 8.5.3. It is a realtime log viewer for docker containers.
Recommendations For versions prior to 8.5.3, update to version 8.5.3 or later, which uses bcrypt for password hashing, to mitigate the risk of rainbow table attacks. As a temporary workaround, consider restricting access to sensitive areas of the application until the update can be applied.

Exploit

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2024-47182
GHSA-W7QR-Q9FH-FJ35
GO-2024-3163
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Dozzle
Suse