Описание
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
Ссылки
EPSS
Процентиль: 36%
0.00424
Низкий
8.1 High
CVSS3
Дефекты
CWE-331
Связанные уязвимости
CVSS3: 8.1
github
8 дней назад
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.
EPSS
Процентиль: 36%
0.00424
Низкий
8.1 High
CVSS3
Дефекты
CWE-331