PT-2024-27673 · Lunary Ai · Lunary

Published

2024-11-14

·

Updated

2024-11-18

·

CVE-2024-3760

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version 1.2.7
Description The issue is related to a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit this by automating forgot password requests to flood targeted user accounts with a high volume of password reset emails. This not only overwhelms the victim's mailbox, making it difficult to manage and locate legitimate emails, but also significantly impacts mail servers by consuming their resources. The increased load can cause performance degradation and, in severe cases, make the mail servers unresponsive or unavailable, disrupting email services for the entire organization.
Recommendations For lunary-ai/lunary version 1.2.7, consider implementing rate limiting on the forgot password page to prevent email bombing attacks. As a temporary workaround, restrict access to the forgot password functionality to minimize the risk of exploitation. Additionally, monitor mail server resources and adjust configurations as needed to prevent performance degradation.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3760

Affected Products

Lunary