CVE-2024-52801: Brute force takeover of OpenID Connect session cookies in sftpgo

5.3 CVSS

Description

sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, FTP/S, WebDAV. The OpenID Connect implementation allows authenticated users to brute force session cookies and thereby gain access to other users' data, since the cookies are generated predictably using the xid library and are therefore unique but not cryptographically secure. This issue was fixed in version v2.6.4, where cookies are opaque and cryptographically secure strings. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Classification

CVE ID: CVE-2024-52801

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

Affected Products

Vendor: drakkan

Product: sftpgo

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://github.com/drakkan/sftpgo/security/advisories/GHSA-6943-qr24-82vx
https://github.com/drakkan/sftpgo/commit/f30a9a2095bf90c0661b04fe038e3b7efc788bc6
https://github.com/rs/xid

Timeline