CVE-2020-14423

Publication date

2020-06-18 13:27:19

Family

mitre

State

PUBLISHED

Description

Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and invitations.