CVE-2018-1000809
Summary
| CVE | CVE-2018-1000809 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-08 15:29:00 UTC |
| Updated | 2019-01-08 16:27:00 UTC |
| Description | privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http request with user=<space>&pass= to /validate/check url. This vulnerability appears to have been fixed in 2.23.2. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Failcounter increments on every token without a PIN when the user= arg only has a <space> · Issue #1227 · privacyidea/privacyidea · GitHub |
CONFIRM |
github.com |
Exploit, Patch, Third Party Advisory |
| Merge branch 'branch-2.23' · privacyidea/privacyidea@a3edc09 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981221 Python (pip) Security Update for privacyIDEA (GHSA-7qqv-r2q4-jxhm)