CVE-2024-47182
CVSS V2 None
CVSS V3 None
Description
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in version 8.5.3.
Overview
- CVE ID
- CVE-2024-47182
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-27T13:58:22.881Z
- Last Modified Date
- 2024-09-27T14:13:09.811Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/amir20/dozzle/security/advisories/GHSA-w7qr-q9fh-fj35 | x_refsource_CONFIRM |
https://github.com/amir20/dozzle/commit/de79f03aa3dbe5bb1e154a7e8d3dccbd229f3ea3 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-47182 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47182 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 15:28:20 | Added to TrackCVE |