CRITICAL🇵🇱 Wersja polska

CVE-2019-10907

CVSS 9.8v3.0pub. 2019-04-07upd. 2024-11-21

Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurityConfig.java. An attacker able to capture cookies might be able to trivially bruteforce offline the passwords of associated users.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Airsonic Project Airsonic

    APP
    Airsonic Project
    10.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-10908CRITICAL9.8PL ✓same product

Airsonic: słaby PRNG umożliwia privilege escalation przez odgadnięcie hasła

CVE-2018-20222CRITICAL9.8PL ✓same product

XXE w Airsonic — zdalne odczytanie plików przed wersją 10.1.2