PT-2024-35447 · Unknown · Password Pusher
Published
2024-10-14
·
Updated
2024-11-21
·
CVE-2024-52796
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Password Pusher versions prior to v1.49.0
Description
The issue is related to the rate limiter in Password Pusher, which can be bypassed by forging proxy headers, allowing bad actors to send unlimited traffic to the site and potentially causing a denial of service. This also enables attackers to more easily execute brute force attacks.
Recommendations
For versions prior to v1.49.0, upgrade to at least v1.49.0 to mitigate this risk.
As a temporary workaround, add rules to your proxy and/or firewall to not accept external proxy headers such as
X-Forwarded-* from clients.
If you are running a remote proxy, authorize the IP address of your remote proxy according to the documentation.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Password Pusher