Weak password requirements in Plone - CVE-2020-7940

 

Weak password requirements in Plone - CVE-2020-7940

Published: February 3, 2020


Vulnerability identifier: #VU24828
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7940
CWE-ID: CWE-521
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to set weak passwords.

The vulnerability exists due to missing password strength checks on the password reset form or the admin form. A remote authenticated attacker can set weak passwords, leading to easier cracking.


Affected software

Plone

How to mitigate CVE-2020-7940

Install updates from vendor's website.


External References

Related Security Bulletins