CVE-2021-27935
Summary
| CVE | CVE-2021-27935 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-03 20:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because the hash of the password is stored in the cookie. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adguard | Adguard Home | All | All | All | All |
| Application | Adguard | Adguard Home | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hash of the password stored in the cookies · Issue #2470 · AdguardTeam/AdGuardHome · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.