CVE-2010-5079
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote…
Does this matter?
Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.
Description
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) "forgot password" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- silverstripe/silverstripe
- Source
- secalert@redhat.com
References
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10Patch
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4Patch, Vendor Advisory
- http://open.silverstripe.org/changeset/114497
- http://open.silverstripe.org/changeset/114498Patch
- http://open.silverstripe.org/changeset/114503Patch
- http://open.silverstripe.org/changeset/114504Patch
- http://open.silverstripe.org/changeset/114505Patch
- http://www.openwall.com/lists/oss-security/2011/01/03/12
- http://www.openwall.com/lists/oss-security/2012/04/30/1
- http://www.openwall.com/lists/oss-security/2012/04/30/3
- http://www.openwall.com/lists/oss-security/2012/05/01/3
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10Patch
- http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4Patch, Vendor Advisory
- http://open.silverstripe.org/changeset/114497
- http://open.silverstripe.org/changeset/114498Patch
- http://open.silverstripe.org/changeset/114503Patch
- http://open.silverstripe.org/changeset/114504Patch
- http://open.silverstripe.org/changeset/114505Patch
- http://www.openwall.com/lists/oss-security/2011/01/03/12
- http://www.openwall.com/lists/oss-security/2012/04/30/1
- http://www.openwall.com/lists/oss-security/2012/04/30/3
- http://www.openwall.com/lists/oss-security/2012/05/01/3
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.