CVE-2024-30187: Medium severity anope vulnerability
Published Mar 25, 2024
·Updated
Anope before 2.0.15 does not prevent resetting the password of a suspended account.
Affected Software
9 affected componentsFixes available
ubuntu/anope<2.0.4-2ubuntu0.1~
2.0.4-2ubuntu0.1~
ubuntu/anope<2.0.6-1ubuntu0.1
2.0.6-1ubuntu0.1
ubuntu/anope<2.0.9-1ubuntu0.1
2.0.9-1ubuntu0.1
ubuntu/anope<2.0.12-1ubuntu0.23.10.1
2.0.12-1ubuntu0.23.10.1
ubuntu/anope<2.0.12-1ubuntu1
2.0.12-1ubuntu1
ubuntu/anope<2.0.15-1
2.0.15-1
ubuntu/anope<2.0.3-1ubuntu0.1~
2.0.3-1ubuntu0.1~
debian/anope<=2.0.6-1, <=2.0.9-1, <=2.0.12-1
2.0.15-1
Anope Anope<2.0.15
Remediation
Event History
Mar 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
Description
Data Sourced
via NVD·08:15 AM
SeverityWeakness
Apr 30, 2024
Data Sourced
via Launchpad·09:54 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-30187?
CVE-2024-30187 has a medium severity rating because it allows resetting passwords for suspended accounts, potentially leading to unauthorized access.
2
How do I fix CVE-2024-30187?
To fix CVE-2024-30187, upgrade Anope to version 2.0.15 or later.
3
Which versions of Anope are vulnerable to CVE-2024-30187?
Versions of Anope prior to 2.0.15, specifically any version below 2.0.15, are vulnerable to CVE-2024-30187.
4
What are the consequences of CVE-2024-30187?
The consequence of CVE-2024-30187 is that it allows attackers to potentially regain access to accounts that were meant to be suspended.
5
Is there a workaround for CVE-2024-30187 until I can upgrade?
A temporary workaround for CVE-2024-30187 is to monitor and manually block any password reset requests for suspended accounts.