CVE-2024-24770Medium· 5.3▾ Sunlitvantage6 vulnerable to a username timing attack on recover password/MFA token
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
Much like https://github.com/vantage6/vantage6/security/advisories/GHSA-45gq-q4xh-cp53, it is possible to find which usernames exist in vantage6 by calling the API routes /recover/lost and /2fa/lost, which send emails to users if they have lost their password or MFA token. Usernames can be found by assessing response time differences, and additionally, they can be found because the endpoint gives a response "Failed to login" if the username exists.
No
No
vantage6 < 4.3.0Upgrade to a patched release:
vantage6 4.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21649High· 8.8vantage6 remote code execution vulnerability
CVE-2023-22738Medium· 6.5vantage6 vulnerable to Improper Preservation of Permissions
CVE-2024-22193Low· 3.5vantage6 may create unencrypted tasks in encrypted collaboration
CVE-2023-41881Low· 3.7vantage6 does not properly delete linked resources when deleting a collaboration
CVE-2023-23930High· 7.2Pickle serialization vulnerable to Deserialization of Untrusted Data
CVE-2023-23929High· 8.8vantage6 refresh tokens do not expire