Описание
SFTPGo has insufficient access control for password reset
Impact
SFTPGo WebAdmin and WebClient support password reset. This feature is disabled in the default configuration. In SFTPGo versions prior to v2.6.1, if the feature is enabled, even users with access restrictions (e.g. expired) can reset their password and log in.
Patches
Fixed in v2.6.1.
Workarounds
The following workarounds are available:
- keep the password reset feature disabled.
- Set a blank email address for users and admins with access restrictions so they cannot receive the email with the reset code and exploit the vulnerability.
Ссылки
- https://github.com/drakkan/sftpgo/security/advisories/GHSA-hw5f-6wvv-xcrh
- https://nvd.nist.gov/vuln/detail/CVE-2024-37897
- https://github.com/drakkan/sftpgo/commit/1f8ac8bfe16100b0484d6c91e1e8361687324423
- https://github.com/drakkan/sftpgo/commit/3462bba3f41cbc75486474991b9e3ac1b5f1e583
- https://github.com/drakkan/sftpgo/releases/tag/v2.6.1
Пакеты
github.com/drakkan/sftpgo/v2
>= 2.2.0, < 2.6.1
2.6.1
EPSS
6.3 Medium
CVSS4
6.5 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and WebClient support password reset. This feature is disabled in the default configuration. In SFTPGo versions prior to v2.6.1, if the feature is enabled, even users with access restrictions (e.g. expired) can reset their password and log in. Users are advised to upgrade to version 2.6.1. Users unable to upgrade may keep the password reset feature disabled or set a blank email address for users and admins with access restrictions so they cannot receive the email with the reset code and exploit the vulnerability.
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S ...
Уязвимость интерфейсов WebAdmin и WebClient сервера обмена и хранения файлов SFTPGo, позволяющая нарушителю обойти существующие ограничения безопасности и повысить свои привилегии
EPSS
6.3 Medium
CVSS4
6.5 Medium
CVSS3