Aller au contenu

Fiche vulnérabilité

CVE-2023-39655 : vulnérabilité critique (CVSS 9.6)

Description

A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords and take over their accounts.

En bref

Sévérité
Critique (CVSS 9.6)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
3 janv. 2024
Dernière mise à jour
18 juin 2025

Références

Rechercher une autre vulnérabilité dans la base CVE