7.5
CVE-2023-25171
- EPSS 0.91%
- Veröffentlicht 15.02.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:14
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Kiwi TCMS has denial of service vulnerability on Password reset page
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Password reset page. An attacker could potentially send a large number of emails if they know the email addresses of users in Kiwi TCMS. Additionally that may strain SMTP resources. Users should upgrade to v12.0 or later to receive a patch. As potential workarounds, users may install and configure a rate-limiting proxy in front of Kiwi TCMS and/or configure rate limits on their email server when possible.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.91% | 0.552 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| security-advisories@github.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
https://kiwitcms.org/blog/kiwi-tcms-team/2023/02/15/kiwi-tcms-120/
https://github.com/kiwitcms/Kiwi/commit/761305d04f5910ba14cc04d1255a8f1afdbb87f3
https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-7j9h-3jxf-3vrf
https://huntr.dev/bounties/3b712cb6-3fa3-4f71-8562-7a7016c6262e