All incidents

Password generator PRNG

Summary

  • CVE: N/A.
  • Product affected: Passbolt Browser Extension.
  • Version affected: v1.6.10 and below
  • Version fixed: v2.0.5.
  • Affected component: Password generator.
  • Vulnerability Type: Use of Dangerous API.
  • Severity: Low (2.3).

Attack vector / exploitation

Credits

Other information

How did you fix this?

Do I need to change my passwords?

Are other part of the code affected?

Event timeline

  • 2018-05-07 17:00 CET: Vulnerability details sent by reporter.
  • 2018-05-07 17:00 CET: We acknowledge the issue, start working on a fix and start looking for similar issues in other part of the code.
  • 2018-05-08 08:30 CET: We release a fix on passbolt development repository and start testing with continuous integration tools.
  • 2018-05-08 09:00 PM CET: We deploy a fix on chrome and firefox web extension stores.
  • 2018-05-08 12:00 PM CET: We notify the reporter that a fix has been deployed.
  • 2018-05-08 12:00 PM CET: We publish the fix on github, the release notes and this report.

Current status:

Last updated: 2018-05-08 12:00 PM CET
Flag of European UnionMade in Europe. Privacy by default.
Passbolt Security Incident Report: vulnerability - May 8th, 2018