CVE-2024-52801 impacts sftpgo, a file transfer solution, specifically its OpenID Connect implementation. Authenticated users can brute force session cookies due to their predictable generation, leading to unauthorized access to other users' data. This vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity, potentially leading to low confidentiality and integrity impacts. The issue was resolved in sftpgo version v2.6.4, where cookies are now cryptographically secure. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Drakkan | Sftpgo | >= 2.3.0, < 2.6.4CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.