All CVEs — page 137 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw lies in Postiz's use of `Math.random()` for generating security-sensitive credentials, which is not cryptographically secure. Attackers can exploit this to reconstruct the PRNG state and derive past and future credentials, compromising user and organization security.
The flaw allows organization members without Git provider access to retrieve plaintext provider credentials, potentially leading to unauthorized access to private repositories or manipulation of external workflows.
The LightRAG login endpoint lacks rate limiting, allowing attackers to perform brute-force password guessing attacks, which can lead to unauthorized access to sensitive documents and administrative operations.