CVE-2012-5507

Description

AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.276

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-plone 4.2.3Windows
Multiple vulnerabilities are fixed in Python-plone 4.3b1Windows
Vulnerabilities CVE-2012-5486,CVE-2012-5507,CVE-2012-6661 are fixed in Python-zope2 2.13.19Windows
Multiple vulnerabilities are fixed in Python-plone for linux 4.2.3Linux
Multiple vulnerabilities are fixed in Python-plone for linux 4.3b1Linux
Vulnerabilities CVE-2012-5486,CVE-2012-5507,CVE-2012-6661 are fixed in Python-zope2 for linux 2.13.19Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234