CVE-2024-57439: Medium severity ruoyi ruoyi-cloud vulnerability
Published Jan 29, 2025
·Updated
An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.
Affected Software
2 affected components
maven/com.ruoyi:ruoyi<=4.8.0
Ruoyi Ruoyi=4.8.0
Event History
Jan 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-57439?
CVE-2024-57439 is classified as a high severity vulnerability due to its potential to cause Denial of Service (DoS).
2
How do I fix CVE-2024-57439?
To mitigate CVE-2024-57439, upgrade to a version of ruoyi later than 4.8.0 where the issue is resolved.
3
Who is affected by CVE-2024-57439?
CVE-2024-57439 affects users of ruoyi v4.8.0 with Admin privileges.
4
What does CVE-2024-57439 exploit?
CVE-2024-57439 exploits the reset password interface to allow duplicate login names.
5
What happens if CVE-2024-57439 is exploited?
If exploited, CVE-2024-57439 can lead to a Denial of Service (DoS), disrupting access to accounts.