CVE-2024-12039: Improper Restriction of Excessive Authentication Attempts in langgenius/dify
langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated attacker to reset owner, admin, or other user passwords within a few hours by guessing the six-digit code, resulting in a complete compromise of the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
langgenius/difyto a version that resolves this vulnerability.Fixed in v0.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12039?
CVE-2024-12039 is considered a high severity vulnerability due to its potential to allow unauthorized password resets.
How do I fix CVE-2024-12039?
To fix CVE-2024-12039, implement rate limiting on code guess attempts for password reset functionality to prevent brute force attacks.
Who is affected by CVE-2024-12039?
Any users of langgenius/dify version v0.10.1 are affected by CVE-2024-12039 due to the password reset vulnerability.
What is the impact of CVE-2024-12039?
The impact of CVE-2024-12039 includes the ability for an attacker to reset user passwords without authentication, compromising user accounts.
When was CVE-2024-12039 disclosed?
CVE-2024-12039 was disclosed in 2024, highlighting a weakness in the password reset process of langgenius/dify.