Insecure Initial Password Generation in Mendix Forgot Password Appstore Module
CVE-2022-26314

9.8CRITICAL

Summary

A significant vulnerability resides in the Mendix Forgot Password Appstore module, which affects various versions. The module generates initial passwords in an insecure manner, creating a potential vector for unauthorized access. This flaw enables unauthenticated remote attackers to exploit the insecure password generation process, allowing them to efficiently brute force passwords under certain circumstances. Remediation steps should be taken to secure initial password setup to prevent unauthorized account access.

Affected Version(s)

Mendix Forgot Password Appstore module All versions >= V3.3.0 < V3.5.1

Mendix Forgot Password Appstore module (Mendix 7 compatible) All versions < V3.2.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.