CVE-2024-42850: Critical severity Silverpeas Silverpeas vulnerability
Published Aug 16, 2024
·Updated
An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
Affected Software
2 affected components
maven/org.silverpeas.core:silverpeas-core<=6.4.2
Silverpeas Silverpeas<=6.4.2
Event History
Aug 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
Affected Software
Advisory Published
via GitHub·09:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-42850?
CVE-2024-42850 is classified with a medium severity due to its potential to allow users to bypass password complexity requirements.
2
How do I fix CVE-2024-42850?
To fix CVE-2024-42850, update Silverpeas to version 6.4.3 or later which addresses this vulnerability.
3
What software is affected by CVE-2024-42850?
CVE-2024-42850 affects Silverpeas versions 6.4.2 and lower.
4
What happens if I am still using Silverpeas v6.4.2 or lower with CVE-2024-42850?
Using Silverpeas v6.4.2 or lower may expose your system to risks as users can bypass password complexity requirements.
5
Is there an official advisory for CVE-2024-42850?
Yes, there are advisories available regarding CVE-2024-42850 that detail the vulnerability and recommended actions.