TROYANOSYVIRUS
Voltar para CVEs

CVE-2024-24554

HIGH
8.2

Descricao

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authenticate against the Bludit API.

Detalhes CVE

Pontuacao CVSS v3.18.2
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado6/24/2024
Ultima modificacao1/2/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

bludit:bludit

Fraquezas (CWE)

CWE-287CWE-338

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.