PT-2024-32464 · Dozzle+1 · Dozzle+1
Mohammed90
·
Published
2024-09-27
·
Updated
2024-11-05
·
CVE-2024-47182
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dozzle versions prior to 8.5.3
Description
The issue concerns the use of an insecure hash for passwords. Specifically, the app uses sha-256, which is susceptible to rainbow table attacks due to its design as a fast message digest hash. This leaves users vulnerable. The app switches to bcrypt, a more secure hash for passwords, in version 8.5.3. It is a realtime log viewer for docker containers.
Recommendations
For versions prior to 8.5.3, update to version 8.5.3 or later, which uses bcrypt for password hashing, to mitigate the risk of rainbow table attacks. As a temporary workaround, consider restricting access to sensitive areas of the application until the update can be applied.
Exploit
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dozzle
Suse