CVE-2024-58360: stoatchat before 0.7.8 Unrestricted Account Creation
stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
stoatchatto a version that resolves this vulnerability.Fixed in 0.7.8 - Configuration
After upgrading to 0.7.8, ensure stoatchat is configured to enforce the protections that were not enforced in versions before 0.7.8: invite-only mode, email verification, captcha, and shield verification.
stoatchat account creation restrictions (invite-only mode, email verification, captcha, shield verification) = enforced/enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58360?
CVE-2024-58360 has a medium severity score of 6.5.
How do I fix CVE-2024-58360?
To fix CVE-2024-58360, upgrade to stoatchat version 0.7.8 or later to enforce account creation restrictions.
What risks are associated with CVE-2024-58360?
CVE-2024-58360 allows attackers to create unlimited accounts, increasing the risk of denial-of-service and compromising service integrity.
What versions of stoatchat are affected by CVE-2024-58360?
CVE-2024-58360 affects all versions of stoatchat prior to 0.7.8.
Does CVE-2024-58360 require user interaction to exploit?
CVE-2024-58360 does not require user interaction to exploit, making it more vulnerable to automated attacks.