Lucene search

K
osvGoogleOSV:GO-2022-0964
HistoryAug 21, 2024 - 4:03 p.m.

SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo

2024-08-2116:03:21
Google
osv.dev
3
sftpgo
recovery codes
abuse
vulnerability
software
github

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

AI Score

6.6

Confidence

Low

SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

AI Score

6.6

Confidence

Low

Related for OSV:GO-2022-0964