Vulnerability Description
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eramba | Eramba | 2.8.1 |
Related Weaknesses (CWE)
References
- https://discussions.eramba.org/t/bug-security-vulnerabilities-not-serious/1650/2Vendor Advisory
- https://gitlab.com/gitlab-com/gl-security/disclosures/-/blob/master/005_eramba/eThird Party Advisory
- https://discussions.eramba.org/t/bug-security-vulnerabilities-not-serious/1650/2Vendor Advisory
- https://gitlab.com/gitlab-com/gl-security/disclosures/-/blob/master/005_eramba/eThird Party Advisory
FAQ
What is CVE-2020-25105?
CVE-2020-25105 is a vulnerability with a CVSS score of 9.8 (CRITICAL). eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
How severe is CVE-2020-25105?
CVE-2020-25105 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-25105?
Check the references section above for vendor advisories and patch information. Affected products include: Eramba Eramba.