CVE-2024-47768: Lif Authentication Server Has No Auth Check When Updating Password In Account Recovery
Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct code. If the attacker knew the email of the target, they could supply the email and immediately prompt the server to update the password without ever needing the code. This issue has been patched in version 1.7.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47768?
CVE-2024-47768 is classified as a moderate severity vulnerability affecting the Lif Authentication Server.
How do I fix CVE-2024-47768?
To fix CVE-2024-47768, ensure proper validation checks are implemented for the account recovery process.
Which versions of Lif Authentication Server are affected by CVE-2024-47768?
CVE-2024-47768 affects all versions of Lif Authentication Server prior to 1.7.3.
What impact does CVE-2024-47768 have on users?
CVE-2024-47768 may allow unauthorized account access due to insufficient verification of recovery email and code.
Is there a patch available for CVE-2024-47768?
Yes, a patch for CVE-2024-47768 is included in Lif Authentication Server version 1.7.3.