CVE-2025-1714

Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and potentially DOS the server
CVSS

No CVSS.

Configurations

No configuration.

History

07 Mar 2025, 05:15

Type Values Removed Values Added
Summary
  • (es) La falta de limitación de velocidad en el flujo de trabajo de registro en Perforce Gliffy anterior a la versión 4.14.0-7 en Gliffy en línea permite al atacante enumerar correos electrónicos de usuarios válidos y potencialmente atacar el servidor
References
  • {'url': 'https://perforce1.lightning.force.com/lightning/r/a91PA000001ScY1YAK/view', 'source': 'security@puppet.com'}
  • () https://portal.perforce.com/s/detail/a91PA000001ScY1YAK -

05 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-05 15:15

Updated : 2025-03-07 05:15


NVD link : CVE-2025-1714

Mitre link : CVE-2025-1714

CVE.ORG link : CVE-2025-1714


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-307

Improper Restriction of Excessive Authentication Attempts