Description
NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table attack (offline attack where hashes of known passwords are precomputed).
Problem types
CWE-759: Use of a One-Way Hash without a Salt
Product status
5.0.0 (semver) before 5.4.6
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2025-53884
github.com/...vector/security/advisories/GHSA-8ff6-pc43-jwv3