PT-2024-23238 · Anope+3 · Anope+3

Ladyfoxy

·

Published

2024-03-25

·

Updated

2024-08-22

·

CVE-2024-30187

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Anope versions prior to 2.0.15
Description The issue allows resetting the password of a suspended account. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 2.0.15, update to version 2.0.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the password reset functionality for suspended accounts until a patch is available.

Exploit

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-30187
USN-6761-1

Affected Products

Anope
Debian
Linuxmint
Ubuntu