CVE-2024-45404

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication and hijack the account. This is because the otpLogin mutation does not implement One Time Password rate limiting. As of time of publication, it is unknown whether a patch is available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*

History

17 May 2025, 02:05

Type Values Removed Values Added
First Time Citeum opencti
Citeum
CWE CWE-307
CPE cpe:2.3:a:citeum:opencti:*:*:*:*:*:*:*:*
References () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-hg56-r6hh-56j7 - () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-hg56-r6hh-56j7 - Vendor Advisory

12 Dec 2024, 17:15

Type Values Removed Values Added
References () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-hg56-r6hh-56j7 - () https://github.com/OpenCTI-Platform/opencti/security/advisories/GHSA-hg56-r6hh-56j7 -
Summary
  • (es) OpenCTI es una plataforma de inteligencia de amenazas cibernéticas de código abierto. En versiones anteriores a la 6.2.18, debido a que no existe la función para limitar la tasa de OTP, un atacante con credenciales válidas o un usuario malintencionado que cometa fraude interno puede vulnerar la autenticación de dos factores y secuestrar la cuenta. Esto se debe a que la mutación otpLogin no implementa la limitación de la tasa de contraseñas de un solo uso. Al momento de la publicación, se desconoce si hay un parche disponible.

12 Dec 2024, 02:02

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 02:02

Updated : 2025-05-17 02:05


NVD link : CVE-2024-45404

Mitre link : CVE-2024-45404

CVE.ORG link : CVE-2024-45404


JSON object : View

Products Affected

citeum

  • opencti
CWE
CWE-287

Improper Authentication

CWE-307

Improper Restriction of Excessive Authentication Attempts