Lucene search

K
cve[email protected]CVE-2024-34695
HistoryMay 14, 2024 - 3:39 p.m.

CVE-2024-34695

2024-05-1415:39:26
CWE-799
web.nvd.nist.gov
7
cve-2024-34695
wargaming's world of warships
reputation system
post creation
api requests
cooldown validation
concurrent karma updates
patch 0.17.4.1

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

WOWS Karma is a reputation system for Wargaming’s World of Warships. A user is able to click multiple times on “create” on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user’s metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.

Affected configurations

Vulners
Node
sakuraisayekiwows_karmaRange0.17.4

CNA Affected

[
  {
    "vendor": "SakuraIsayeki",
    "product": "WOWS-Karma",
    "versions": [
      {
        "version": "<= 0.17.4",
        "status": "affected"
      }
    ]
  }
]

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Related for CVE-2024-34695