Back

HIGH

OpenCTI's lack of Rate Limit lead to OTP brute forcing

Published Dec 11, 2024

Description

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication and hijack the account. This is because the otpLogin mutation does not implement One Time Password rate limiting. As of time of publication, it is unknown whether a patch is available.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Dec 11, 2024
Updated Dec 12, 2024
Reserved Aug 28, 2024

CISA Vulnrichment

Updated Dec 12, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Dec 11, 2024
Updated Dec 12, 2024

GitHub

No data