Host Header Injection Vulnerability in Perfood Couch Auth Package
CVE-2023-39655

9.6CRITICAL

Key Information:

Vendor

Perfood

Status
Vendor
CVE Published:
3 January 2024

What is CVE-2023-39655?

A host header injection vulnerability has been identified in the Perfood Couch Auth package. This vulnerability occurs when a specially crafted host header is supplied during the password reset process. By exploiting this flaw, an attacker can redirect users to an unauthorized server controlled by them, thus leaking sensitive information such as the password reset token. This vulnerability poses a significant risk as it enables attackers to initiate password resets for other users, potentially leading to unauthorized account access and control. It is crucial for users of the affected versions to implement mitigations to safeguard against this type of attack.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.