Password Reset Link Vulnerability in Enalean Tuleap
CVE-2018-17298

9.8CRITICAL

Key Information:

Vendor

Enalean

Status
Vendor
CVE Published:
21 September 2018

What is CVE-2018-17298?

A security flaw in Enalean Tuleap allows password reset links to remain valid even after a user successfully changes their password. This oversight can potentially expose users to unauthorized access, as anyone with access to these reset links can reset the passwords without detection. It’s crucial for systems dealing with sensitive information to ensure that all authentication and password processes invalidate outdated or unused links to maintain user security and privacy.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.