漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Secret encryption vulnerable to brute-force attacks
Vulnerability Description
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key. Users on version 8.0.0 and above are automatically migrated away from the weak encoding on first login. Users should destroy encrypted backups made with versions prior to 8.0.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
口令使用弱密码学算法
Vulnerability Title
Authenticator 安全漏洞
Vulnerability Description
Authenticator是Authenticator Extension开源的一个身份验证器。 Authenticator 7.0.0版本及之前版本存在安全漏洞,该漏洞源于用户数据加密密钥仅使用AES-256和EVP_BytesToKey KDF进行存储,这可能导致攻击者通过暴力破解获取用户的加密密钥。
CVSS Information
N/A
Vulnerability Type
N/A