authenticator CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

authenticator 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to authenticator, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2024-45394 Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key. Users on version 8.0.0 and above are automatically migrated away from the weak encoding on first login. Users should destroy encrypted backups made with versions prior to 8.0.0. [email protected] 8.8 0.09% 2024-09-03 2024-10-09
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence