Vulnerability Description
libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.
CVSS Score
9.8
CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache Authenhook Project | Apache Authenhook | 2.00-04 |
Related Weaknesses (CWE)
References
- http://seclists.org/oss-sec/2010/q4/63Mailing ListThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=599712PatchThird Party Advisory
- https://rt.cpan.org/Public/Bug/Display.html?id=62040PatchThird Party Advisory
- http://seclists.org/oss-sec/2010/q4/63Mailing ListThird Party Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=599712PatchThird Party Advisory
- https://rt.cpan.org/Public/Bug/Display.html?id=62040PatchThird Party Advisory
FAQ
What is CVE-2010-3845?
CVE-2010-3845 is a vulnerability with a CVSS score of 9.8 (CRITICAL). libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.
How severe is CVE-2010-3845?
CVE-2010-3845 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2010-3845?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Authenhook Project Apache Authenhook.