Email Bombing Vulnerability in Lunary version 1.2.7
CVE-2024-3760

7.5HIGH

Key Information:

Vendor

lunary-ai

Status
Vendor
CVE Published:
14 November 2024

What is CVE-2024-3760?

In version 1.2.7 of Lunary.AI, a lack of rate limiting on the forgot password page allows attackers to automate requests, leading to an email bombing scenario. This vulnerability enables malicious actors to inundate targeted user accounts with excessive password reset emails, complicating the users' ability to manage their inbox and locate legitimate communications. Furthermore, this influx of emails places a significant burden on mail servers, potentially leading to degraded performance and, in extreme cases, total unavailability of email services for affected organizations. This creates a substantial risk to the integrity and functionality of users' communication channels.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.