VDB
BDU%3A2023-02338
BDU%3A2023-02338
PUBLISHED
CVSS 4.900000095367432 MEDIUM
Уязвимость реализации алгоритма хеширования bcrypt библиотеки для экспорта файлов системы Prometheus Exporter Toolkit, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
4.900000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения | SUSE Linux Enterprise Server for SAP Applications, openSUSE Tumbleweed, SUSE CaaS Platform, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, OpenSUSE Leap, SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, Red Hat OpenShift Container Platform, Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, Red Hat Enterprise Linux, SUSE Manager Tools, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Module for Package Hub, SUSE Linux Enterprise Module for SAP Applications, Exporter Toolkit |
Timeline
- May 4, 2023 CVE Published
References
- http://www.openwall.com/lists/oss-security/2022/11/29/1 url
- http://www.openwall.com/lists/oss-security/2022/11/29/2 url
- http://www.openwall.com/lists/oss-security/2022/11/29/4 url
- https://github.com/prometheus/exporter-toolkit/security/advisories/GHSA-7rg2-cxvp-9p7p url
- https://www.suse.com/security/cve/CVE-2022-46146.html url
- https://vuldb.com/ru/?id.214520 url
- https://github.com/prometheus/exporter-toolkit/commit/5b1eab34484ddd353986bce736cd119d863e4ff5 advisory
- https://access.redhat.com/security/cve/cve-2022-46146 advisory
- https://www.suse.com/security/cve/CVE-2022-46146.htm advisory