CollabNet Subversion Edge Management Credential Leak

Discussion in 'News Aggregator' started by Packet Storm, 30 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    The CollabNet Subversion Edge Management Frontend leaks the unsalted MD5 hash of password of the currently logged in user via a "POST /csvn/user/index" request. An attacker that exploits an XSS or has gained a valid session via other means is able to retrieve the unsalted MD5 hash of the corresponding user and easily crack the hash in order to know the users password. Fixed in version 5.0.

    Continue reading...
     

Share This Page

Loading...