Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjfr-89c6-m7cf

Опубликовано: 06 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue lies in the backend's handling of the reset password process, where the token, once used, is not discarded or invalidated, enabling its reuse. This vulnerability could lead to unauthorized account access if an attacker obtains the recovery token.

In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue lies in the backend's handling of the reset password process, where the token, once used, is not discarded or invalidated, enabling its reuse. This vulnerability could lead to unauthorized account access if an attacker obtains the recovery token.

EPSS

Процентиль: 34%
0.00138
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

In lunary-ai/lunary version 1.2.4, a vulnerability exists in the password recovery mechanism where the reset password token is not invalidated after use. This allows an attacker who compromises the recovery token to repeatedly change the password of a victim's account. The issue lies in the backend's handling of the reset password process, where the token, once used, is not discarded or invalidated, enabling its reuse. This vulnerability could lead to unauthorized account access if an attacker obtains the recovery token.

CVSS3: 6.4
fstec
почти 2 года назад

Уязвимость платформы для мониторинга, управления и улучшения приложений LLM Lunary, связанная с недостатком механизма восстановления пароля, позволяющая нарушителю использовать токен восстановления для многократной смены пароля пользователя

EPSS

Процентиль: 34%
0.00138
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-640