Improper Access Control Affecting anope/anope package, versions [,2.0.15)


0.0
medium

Snyk CVSS

    Attack Complexity Low

    Threat Intelligence

    EPSS 0.04% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-UNMANAGED-ANOPEANOPE-6483322
  • published 25 Mar 2024
  • disclosed 25 Mar 2024
  • credit LadyFoxy

How to fix?

Upgrade anope/anope to version 2.0.15 or higher.

Overview

Affected versions of this package are vulnerable to Improper Access Control due to improper security checks in the process of password resetting. An attacker can reset the password of a suspended account by exploiting this vulnerability.