First published: Mon Mar 25 2024(Updated: )
Anope before 2.0.15 does not prevent resetting the password of a suspended account.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/anope | <2.0.4-2ubuntu0.1~ | 2.0.4-2ubuntu0.1~ |
ubuntu/anope | <2.0.6-1ubuntu0.1 | 2.0.6-1ubuntu0.1 |
ubuntu/anope | <2.0.9-1ubuntu0.1 | 2.0.9-1ubuntu0.1 |
ubuntu/anope | <2.0.12-1ubuntu0.23.10.1 | 2.0.12-1ubuntu0.23.10.1 |
ubuntu/anope | <2.0.12-1ubuntu1 | 2.0.12-1ubuntu1 |
ubuntu/anope | <2.0.15-1 | 2.0.15-1 |
ubuntu/anope | <2.0.3-1ubuntu0.1~ | 2.0.3-1ubuntu0.1~ |
debian/anope | <=2.0.6-1<=2.0.9-1<=2.0.12-1 | 2.0.15-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30187 has a medium severity rating because it allows resetting passwords for suspended accounts, potentially leading to unauthorized access.
To fix CVE-2024-30187, upgrade Anope to version 2.0.15 or later.
Versions of Anope prior to 2.0.15, specifically any version below 2.0.15, are vulnerable to CVE-2024-30187.
The consequence of CVE-2024-30187 is that it allows attackers to potentially regain access to accounts that were meant to be suspended.
A temporary workaround for CVE-2024-30187 is to monitor and manually block any password reset requests for suspended accounts.