CVE-2011-2190Cherokee vulnerability

CWE-3106 documents4 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 75.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 7
Latest updateMay 17

Description

The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8m6g-w6v9-3j2m: The generate_admin_password function in Cherokee before 12022-05-17
CVEList
CVE-2011-2190: The generate_admin_password function in Cherokee before 12011-10-07

💬Community

3
Bugzilla
CVE-2011-2190 CVE-2011-2191 cherokee: multiple vulnerabilities [epel-all]2011-06-14
Bugzilla
CVE-2011-2190 CVE-2011-2191 cherokee: multiple vulnerabilities [fedora-all]2011-06-14
Bugzilla
CVE-2011-2190 cherokee: A weakness in Cherokee's administrative interface random administrator password generation2011-06-03
CVE-2011-2190 — Cherokee-project Cherokee vulnerability | cvebase