Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqh6-6h6c-366m

Опубликовано: 03 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

CouchAuth host header injection vulnerability leaks the password reset token

A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords and take over their accounts.

Пакеты

Наименование

@perfood/couch-auth

npm
Затронутые версииВерсия исправления

<= 0.20.0

Отсутствует

EPSS

Процентиль: 29%
0.00104
Низкий

8.1 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.6
nvd
около 2 лет назад

A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords and take over their accounts.

EPSS

Процентиль: 29%
0.00104
Низкий

8.1 High

CVSS3

Дефекты

CWE-74