Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and potentially DOS the server
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://portal.perforce.com/s/detail/a91PA000001ScY1YAK |
|
History
Fri, 07 Mar 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Mar 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Username Enumeration in Gliffy | |
| References |
|
Wed, 05 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and potentially DOS the server | |
| Weaknesses | CWE-200 CWE-307 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Perforce
Published: 2025-03-05T14:56:53.962Z
Updated: 2025-03-07T04:37:18.431Z
Reserved: 2025-02-26T10:48:12.335Z
Link: CVE-2025-1714
Updated: 2025-03-05T16:20:17.562Z
Status : Received
Published: 2025-03-05T15:15:15.413
Modified: 2025-03-07T05:15:16.233
Link: CVE-2025-1714
No data.