Vulnerability Name: | CVE-2013-1895 (CCN-83039) | ||||||||||||
Assigned: | 2013-03-18 | ||||||||||||
Published: | 2013-03-18 | ||||||||||||
Updated: | 2020-02-04 | ||||||||||||
Summary: | The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-307 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-1895 Source: MISC Type: Third Party Advisory, Tool Signature http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101382.html Source: MISC Type: Third Party Advisory http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101387.html Source: CCN Type: SA52701 Python py-bcrypt Module Security Bypass Vulnerability Source: MISC Type: Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2013/03/26/2 Source: CCN Type: BID-58702 Python 'py-bcrypt' Module CVE-2013-1895 Authentication Bypass Vulnerability Source: MISC Type: Third Party Advisory, VDB Entry http://www.securityfocus.com/bid/58702 Source: CCN Type: bcrypt blowfish password hashing for Python Revision: 3bc365ff4373 Source: MISC Type: Third Party Advisory, VDB Entry https://exchange.xforce.ibmcloud.com/vulnerabilities/83039 Source: XF Type: UNKNOWN python-cve20131895-sec-bypass(83039) Source: CCN Type: Python Web site py-bcrypt Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-1895 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |