CVE-2024-24553: Bludit
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.
Affected products
- Bludit Bludit: from 3.14.0, up to and including 3.15.0
Published 2024-06-24. Last modified 2026-06-17.