PT-2024-29781 · Fiware · Fiware Keyrock

Wolfgang Hotwagner

·

Published

2024-08-12

·

Updated

2024-08-29

·

CVE-2024-42164

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FIWARE Keyrock versions <= 8.4
Description The issue is related to insufficiently random values used for generating password reset tokens, allowing attackers to predict the token and disable two-factor authorization for any user. This makes it easier for attackers to guess tokens and take over accounts.
Recommendations For FIWARE Keyrock versions <= 8.4, patch immediately to address the issue. Additionally, monitor for suspicious password resets as a precautionary measure.

Exploit

Fix

Improper Authentication

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2024-42164

Affected Products

Fiware Keyrock