CVE Vulnerabilities

CVE-2024-34113

Weak Encoding for Password

Published: Jun 13, 2024 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation that compromises the confidentiality of password data. An attacker could exploit this weakness to decrypt or guess passwords, potentially gaining unauthorized access to protected resources. Exploitation of this issue does not require user interaction.

Weakness

Obscuring a password with a trivial encoding does not protect the password.

Affected Software

NameVendorStart VersionEnd Version
ColdfusionAdobe2021-update1 (including)2021-update1 (including)
ColdfusionAdobe2021-update10 (including)2021-update10 (including)
ColdfusionAdobe2021-update11 (including)2021-update11 (including)
ColdfusionAdobe2021-update12 (including)2021-update12 (including)
ColdfusionAdobe2021-update13 (including)2021-update13 (including)
ColdfusionAdobe2021-update2 (including)2021-update2 (including)
ColdfusionAdobe2021-update3 (including)2021-update3 (including)
ColdfusionAdobe2021-update4 (including)2021-update4 (including)
ColdfusionAdobe2021-update5 (including)2021-update5 (including)
ColdfusionAdobe2021-update6 (including)2021-update6 (including)
ColdfusionAdobe2021-update7 (including)2021-update7 (including)
ColdfusionAdobe2021-update8 (including)2021-update8 (including)
ColdfusionAdobe2021-update9 (including)2021-update9 (including)
ColdfusionAdobe2023-update1 (including)2023-update1 (including)
ColdfusionAdobe2023-update2 (including)2023-update2 (including)
ColdfusionAdobe2023-update3 (including)2023-update3 (including)
ColdfusionAdobe2023-update4 (including)2023-update4 (including)
ColdfusionAdobe2023-update5 (including)2023-update5 (including)
ColdfusionAdobe2023-update6 (including)2023-update6 (including)
ColdfusionAdobe2023-update7 (including)2023-update7 (including)

Potential Mitigations

References