PT-2024-28845 · Sftpgo · Sftpgo
Published
2024-07-22
·
Updated
2024-09-13
·
CVE-2024-40430
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SFTPGO version 2.6.2
Description
The issue concerns the JWT implementation in SFTPGO, which lacks certain security measures such as using JWT ID (JTI) claims, nonces, and proper expiration and invalidation mechanisms. However, it is noted that exploiting this issue would require an attacker to steal another user's cookie, and SFTPGo validates cookies by the IP address they were issued to, making stolen cookies from different IP addresses ineffective. The attack vector described requires an attacker to gain access to a user's session cookie, essentially making them the valid user with expected access to user data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sftpgo