PT-2019-17963 · Nicehash · Nicehash Miner
Ashutosh Barot
·
Publicado
2019-11-06
·
Atualizado
2020-08-24
·
CVE-2019-6120
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NiceHash Miner versions prior to 2.0.3.0
Description
A missing rate limit in the process of adding a wallet via email address allows remote attackers to submit a large number of email addresses, potentially identifying valid ones. This issue can be exploited in conjunction with a username enumeration technique to enumerate a large number of valid users' email addresses.
Recommendations
For versions prior to 2.0.3.0, update to version 2.0.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the wallet addition feature via email address to minimize the risk of exploitation.
Exploit
Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nicehash Miner