PT-2024-35452 · Sftpgo+1 · Sftpgo+1

Denisvr72

·

Published

2024-11-29

·

Updated

2024-12-11

·

CVE-2024-52801

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions sftpgo versions prior to v2.6.4
Description The OpenID Connect implementation in sftpgo allows authenticated users to brute force session cookies, gaining access to other users' data. This is because the cookies are generated predictably using the xid library and are unique but not cryptographically secure.
Recommendations For versions prior to v2.6.4, upgrade to version v2.6.4 or later, where cookies are opaque and cryptographically secure strings. As a temporary workaround, consider restricting access to the OpenID Connect implementation until a patch is available. Avoid using the predictably generated session cookies in the affected API endpoints until the issue is resolved.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2024-52801
GHSA-6943-QR24-82VX
GO-2024-3300
OPENSUSE-SU-2024:14567-1

Affected Products

Sftpgo
Xid