PT-2016-4411 · Apache · Apache Openmeetings

Andreas Lindh

·

Publicado

2016-04-11

·

Atualizado

2018-10-09

·

CVE-2016-0783

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache OpenMeetings versions prior to 3.1.1
Description The issue allows remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time, due to the generation of predictable password reset tokens by the sendHashByUser function.
Recommendations For versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the password reset functionality until the update is applied.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-0783

Produtos afetados

Apache Openmeetings