CVE-2012-3798
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
27/06/2012
Last modified:
11/04/2025
Description
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when creating a local user account, allows attackers to obtain part of the initial input used to generate passwords, which makes it easier to conduct brute force password guessing attacks.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bryce_hamrick:janrain_capture:6.x-1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:bryce_hamrick:janrain_capture:7.x-1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



