SFTPGo has insufficient access control for password reset
Package
Affected versions
>= 2.2.0, < 2.6.1
Patched versions
2.6.1
Description
Published to the GitHub Advisory Database
Jun 20, 2024
Reviewed
Jun 20, 2024
Published by the National Vulnerability Database
Jun 20, 2024
Last updated
Aug 8, 2024
Impact
SFTPGo WebAdmin and WebClient support password reset. This feature is disabled in the default configuration.
In SFTPGo versions prior to v2.6.1, if the feature is enabled, even users with access restrictions (e.g. expired) can reset their password and log in.
Patches
Fixed in v2.6.1.
Workarounds
The following workarounds are available:
References