Show plain JSON{"containers": {"cna": {"affected": [{"product": "n/a", "vendor": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}], "descriptions": [{"lang": "en", "value": "SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) \"forgot password\" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors."}], "problemTypes": [{"descriptions": [{"description": "n/a", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2012-09-17T17:00:00Z", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat"}, "references": [{"tags": ["x_refsource_CONFIRM"], "url": "http://open.silverstripe.org/changeset/114505"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://open.silverstripe.org/changeset/114503"}, {"name": "[oss-security] 20120501 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST"], "url": "http://www.openwall.com/lists/oss-security/2012/05/01/3"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://open.silverstripe.org/changeset/114504"}, {"name": "[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/1"}, {"name": "[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/3"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://open.silverstripe.org/changeset/114498"}, {"name": "[oss-security] 20110104 CVE request: silverstripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST"], "url": "http://www.openwall.com/lists/oss-security/2011/01/03/12"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://open.silverstripe.org/changeset/114497"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10"}], "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "secalert@redhat.com", "ID": "CVE-2010-5079", "STATE": "PUBLIC"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "n/a", "version": {"version_data": [{"version_value": "n/a"}]}}]}, "vendor_name": "n/a"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin, (3) \"forgot password\" functionality, and (4) password salts, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "n/a"}]}]}, "references": {"reference_data": [{"name": "http://open.silverstripe.org/changeset/114505", "refsource": "CONFIRM", "url": "http://open.silverstripe.org/changeset/114505"}, {"name": "http://open.silverstripe.org/changeset/114503", "refsource": "CONFIRM", "url": "http://open.silverstripe.org/changeset/114503"}, {"name": "[oss-security] 20120501 Re: CVE-request: SilverStripe before 2.4.4", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/05/01/3"}, {"name": "http://open.silverstripe.org/changeset/114504", "refsource": "CONFIRM", "url": "http://open.silverstripe.org/changeset/114504"}, {"name": "[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/04/30/1"}, {"name": "[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/04/30/3"}, {"name": "http://open.silverstripe.org/changeset/114498", "refsource": "CONFIRM", "url": "http://open.silverstripe.org/changeset/114498"}, {"name": "[oss-security] 20110104 CVE request: silverstripe before 2.4.4", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2011/01/03/12"}, {"name": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4", "refsource": "CONFIRM", "url": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4"}, {"name": "http://open.silverstripe.org/changeset/114497", "refsource": "CONFIRM", "url": "http://open.silverstripe.org/changeset/114497"}, {"name": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10", "refsource": "CONFIRM", "url": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10"}]}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-07T04:09:38.942Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://open.silverstripe.org/changeset/114505"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://open.silverstripe.org/changeset/114503"}, {"name": "[oss-security] 20120501 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST", "x_transferred"], "url": "http://www.openwall.com/lists/oss-security/2012/05/01/3"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://open.silverstripe.org/changeset/114504"}, {"name": "[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST", "x_transferred"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/1"}, {"name": "[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST", "x_transferred"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/3"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://open.silverstripe.org/changeset/114498"}, {"name": "[oss-security] 20110104 CVE request: silverstripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST", "x_transferred"], "url": "http://www.openwall.com/lists/oss-security/2011/01/03/12"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://open.silverstripe.org/changeset/114497"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://doc.silverstripe.org/framework/en/trunk/changelogs//2.3.10"}]}]}, "cveMetadata": {"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2010-5079", "datePublished": "2012-09-17T17:00:00Z", "dateReserved": "2011-12-19T00:00:00Z", "dateUpdated": "2024-09-16T21:07:45.153Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}