CVE-2024-55885
Severity CVSS v4.0:
MEDIUM
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
12/12/2024
Last modified:
01/08/2025
Description
beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded opponents due to its vulnerability to collision attacks. Version 2.3.4 replaces MD5 with SHA256.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:beego:beego:*:*:*:*:*:*:*:* | 2.3.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page