CVE-2020-27687: Input Validation
ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-27687.
What is the severity of CVE-2020-27687?
The severity of CVE-2020-27687 is high with a severity value of 8.8.
What does the vulnerability CVE-2020-27687 allow an attacker to do?
The vulnerability CVE-2020-27687 allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server.
How does the vulnerability CVE-2020-27687 occur?
The vulnerability CVE-2020-27687 occurs due to the lack of validation of the Host header in password-reset emails.
Is there a fix available for CVE-2020-27687?
Yes, upgrading to ThingsBoard version 3.2 or later fixes the vulnerability CVE-2020-27687.