CVE-2023-4641

MEDIUM WAF: Low
CVSS 5.5 Published: 2023-12-27
CWE-287

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
shadow-maintshadow-utilsup to 4.14.0
redhatcodeready_linux_builder8.0
redhatcodeready_linux_builder9.0
redhatcodeready_linux_builder_for_arm648.0_aarch64
redhatcodeready_linux_builder_for_arm649.0_aarch64
redhatcodeready_linux_builder_for_ibm_z_systems8.0_s390x
redhatcodeready_linux_builder_for_ibm_z_systems9.0_s390x
redhatcodeready_linux_builder_for_power_little_endian8.0_ppc64le
redhatcodeready_linux_builder_for_power_little_endian9.0_ppc64le
redhatenterprise_linux8.0

References

Back to CVE Database