Lack of Rate Limiting in Perforce Gliffy Email Sign-up Workflow
CVE-2025-1714

6.9MEDIUM

Key Information:

Vendor

Perforce

Status
Vendor
CVE Published:
5 March 2025

What is CVE-2025-1714?

The Gliffy online application by Perforce has a vulnerability in its sign-up workflow that lacks proper rate limiting. This oversight allows attackers to enumerate valid user emails, posing a security risk. Furthermore, the vulnerability could lead to denial of service (DoS) conditions, impacting the overall availability of the server. Users are encouraged to upgrade to version 4.14.0-7 or later to mitigate these risks.

Affected Version(s)

Gliffy 0 < 4.14.0-7

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.