PT-2024-27673 · Lunary Ai · Lunary
Published
2024-11-14
·
Updated
2024-11-18
·
CVE-2024-3760
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version 1.2.7
Description
The issue is related to a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit this by automating forgot password requests to flood targeted user accounts with a high volume of password reset emails. This not only overwhelms the victim's mailbox, making it difficult to manage and locate legitimate emails, but also significantly impacts mail servers by consuming their resources. The increased load can cause performance degradation and, in severe cases, make the mail servers unresponsive or unavailable, disrupting email services for the entire organization.
Recommendations
For lunary-ai/lunary version 1.2.7, consider implementing rate limiting on the forgot password page to prevent email bombing attacks. As a temporary workaround, restrict access to the forgot password functionality to minimize the risk of exploitation. Additionally, monitor mail server resources and adjust configurations as needed to prevent performance degradation.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lunary