CVE-2024-37897

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-37897
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-37897.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-37897
Aliases
Related
Published
2024-06-20T18:15:13Z
Modified
2025-01-08T16:10:21.008781Z
Summary
[none]
Details

SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and WebClient support password reset. This feature is disabled in the default configuration. In SFTPGo versions prior to v2.6.1, if the feature is enabled, even users with access restrictions (e.g. expired) can reset their password and log in. Users are advised to upgrade to version 2.6.1. Users unable to upgrade may keep the password reset feature disabled or set a blank email address for users and admins with access restrictions so they cannot receive the email with the reset code and exploit the vulnerability.

References

Affected packages

Git / github.com/drakkan/sftpgo

Affected ranges

Type
GIT
Repo
https://github.com/drakkan/sftpgo
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

0.*

0.9.1
0.9.2
0.9.3
0.9.4
0.9.5
0.9.6

v1.*

v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.2.2

v2.*

v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.2.0
v2.2.1
v2.3.0
v2.4.0
v2.5.0
v2.5.1
v2.6.0