PT-2023-17384 · Answerdev · Answerdev/Answer

Published

2023-04-11

·

Updated

2024-08-20

·

CVE-2023-1976

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

answerdev/answer versions prior to 1.1.0

Description:

The issue concerns password aging with long expiration in the answerdev/answer GitHub repository. Specifically, the problem is that password reset links do not expire, making the system vulnerable to account takeover. This is a significant concern for security as it could allow unauthorized access to accounts.

Recommendations:

For versions prior to 1.1.0, update to version 1.1.0 or later to resolve the issue. As a temporary workaround, consider implementing additional security measures such as restricting access to password reset functionality or monitoring for suspicious activity.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-1976
GHSA-J97G-77FJ-9C4P
GO-2023-1719

Affected Products

Answerdev/Answer