Truncated Passwords Can Still Pose a Risk to Password Security
CVE-2024-9683

4.8MEDIUM

Key Information:

Vendor
CVE Published:
17 October 2024

What is CVE-2024-9683?

A vulnerability has been identified in Quay that allows successful user authentication even when only a truncated version of a password is used. This issue undermines the security integrity of password enforcement mechanisms, leading to potential weaknesses in the authentication process. While the standard length for passwords utilized typically reaches 73 characters, this vulnerability exploits the truncation, rendering it easier for attackers to perform brute-force or password-guessing attacks. Consequently, the overall effectiveness of password policies may be compromised, leaving systems at an increased risk of unauthorized access in the long run.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Alexander Pryor for reporting this issue.
.
CVE-2024-9683 : Truncated Passwords Can Still Pose a Risk to Password Security