CVE-2024-47182
MEDIUMDescription
Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible to rainbow table attacks. The app switches to bcrypt, a more appropriate hash for passwords, in version 8.5.3.
Is your site exposed to CVE-2024-47182?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| amirraminfar | dozzle |
References
Frequently Asked Questions
What is CVE-2024-47182? +
How severe is CVE-2024-47182? +
What products are affected by CVE-2024-47182? +
How do I check if I'm vulnerable to CVE-2024-47182? +
Related Vulnerabilities
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making …
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically …
free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API format. In versions up …
R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to …
### Impact When this library is used to deserialize messagepack data from an untrusted source, there is a risk of …
Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographically …