In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit this by automating forgot password requests to flood targeted user accounts with a high volume of password reset emails. This not only overwhelms the victim's mailbox, making it difficult to manage and locate legitimate emails, but also significantly impacts mail servers by consuming their resources. The increased load can cause performance degradation and, in severe cases, make the mail servers unresponsive or unavailable, disrupting email services for the entire organization.
History

Mon, 18 Nov 2024 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Lunary
Lunary lunary
CPEs cpe:2.3:a:lunary:lunary:*:*:*:*:*:*:*:*
Vendors & Products Lunary
Lunary lunary

Mon, 18 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Lunary-ai
Lunary-ai lunary-ai\/lunary
CPEs cpe:2.3:a:lunary-ai:lunary-ai\/lunary:*:*:*:*:*:*:*:*
Vendors & Products Lunary-ai
Lunary-ai lunary-ai\/lunary
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 18:30:00 +0000

Type Values Removed Values Added
Description In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit this by automating forgot password requests to flood targeted user accounts with a high volume of password reset emails. This not only overwhelms the victim's mailbox, making it difficult to manage and locate legitimate emails, but also significantly impacts mail servers by consuming their resources. The increased load can cause performance degradation and, in severe cases, make the mail servers unresponsive or unavailable, disrupting email services for the entire organization.
Title Email Bombing Vulnerability in lunary-ai/lunary
Weaknesses CWE-770
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-11-14T18:26:21.685Z

Updated: 2024-11-18T20:42:08.530Z

Reserved: 2024-04-13T16:17:34.211Z

Link: CVE-2024-3760

cve-icon Vulnrichment

Updated: 2024-11-18T20:40:40.665Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-14T19:15:06.327

Modified: 2024-11-18T22:02:15.053

Link: CVE-2024-3760

cve-icon Redhat

No data.