CVE-2018-1000809

Source
https://cve.org/CVERecord?id=CVE-2018-1000809
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-1000809.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-1000809
Aliases
Published
2018-10-08T15:29:01Z
Modified
2026-05-17T11:53:58Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http request with user=&pass= to /validate/check url. This vulnerability appears to have been fixed in 2.23.2.

References

Affected packages