PT-2024-31402 · Unknown · Ringer Server

Superior126

·

Published

2024-09-04

·

Updated

2024-09-05

·

CVE-2024-45050

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ringer server versions prior to 1.3.1
Description The issue concerns the messages loading route in the Ringer server, where it fails to verify if the user loading a conversation is actually a member of that conversation. This allows any user with a Lif Account to load any conversation between two users without permission. The problem was solved in version 1.3.1.
Recommendations For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the messages loading route until the patch is applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-45050
GHSA-CPC7-79CG-QV65

Affected Products

Ringer Server