Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of the target, they could supply the email and immediately prompt the server to update the password without ever needing the code. This issue has been patched in version 1.7.3.
History

Wed, 13 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Lifplatforms
Lifplatforms lif Authentication Server
Weaknesses CWE-862
CPEs cpe:2.3:a:lifplatforms:lif_authentication_server:*:*:*:*:*:*:*:*
Vendors & Products Lifplatforms
Lifplatforms lif Authentication Server
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 04 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Oct 2024 14:45:00 +0000

Type Values Removed Values Added
Description Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of the target, they could supply the email and immediately prompt the server to update the password without ever needing the code. This issue has been patched in version 1.7.3.
Title Lif Authentication Server Has No Auth Check When Updating Password In Account Recovery
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-04T14:33:59.020Z

Updated: 2024-10-04T16:02:58.471Z

Reserved: 2024-09-30T21:28:53.232Z

Link: CVE-2024-47768

cve-icon Vulnrichment

Updated: 2024-10-04T16:02:54.276Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-04T15:15:13.323

Modified: 2024-11-13T14:55:39.690

Link: CVE-2024-47768

cve-icon Redhat

No data.