CVE-2015-3454
high
CVSS v3
7.5
CVSS v2
5.0
VIR risk
7.5
Description
TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to obtain password hashes via a cross-site scripting attack.
Predictions
Exploit likelihood
83%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://github.com/VulcanJS/Vulcan/commit/827a15dc7422b2447f3a2e395b5e511379002ea4
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| vulcanjs | vulcan | {"endIncluding":"0.14.3"} | |
References
- http://www.openwall.com/lists/oss-security/2015/04/29/8
- http://www.securityfocus.com/bid/74331
- https://github.com/VulcanJS/Vulcan/commit/827a15dc7422b2447f3a2e395b5e511379002ea4
- https://github.com/VulcanJS/Vulcan/issues/838
- http://www.openwall.com/lists/oss-security/2015/04/29/8
- http://www.securityfocus.com/bid/74331
- https://github.com/VulcanJS/Vulcan/commit/827a15dc7422b2447f3a2e395b5e511379002ea4
- https://github.com/VulcanJS/Vulcan/issues/838
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.