Security Advisory

CVE-2020-14423

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-06-18 13:27:19
Last updated 2024-08-04 12:46:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.