Junglewise Threat Intelligence

Cartalyst Sentry account takeover via null password reset codes

Severity: high · CVSS 8.9 · Published 2024-05-15

Technologies: Cartalyst Sentry. Vendors: Packagist.

Executive brief

A security flaw in the Sentry authentication library, used by the OpenCFP conference management system, allows unauthorized individuals to take over user accounts. By exploiting a weakness in how the system verifies password reset requests, an attacker can reset the password of any user who does not have an active reset request pending. This could lead to a full compromise of the platform, including access to sensitive speaker data and administrative controls.

Technical details

The vulnerability exists in the `checkResetPasswordCode()` function within the Cartalyst Sentry authentication framework. The database schema defaults the `reset_password_code` column to NULL for users who have not requested a password reset. Due to loose comparison or improper validation, providing a NULL value (via a missing parameter or a URL null byte `%00`) in the password reset request causes the check to return true. An attacker can exploit this by sending a POST request to the password update endpoint with a target `user_id` and a null `reset_code`. While the attacker needs to know the victim's email to log in after the reset, numeric user IDs are often predictable (e.g., IDs 1-5 for administrators). The issue is fixed in Sentry version 2.1.7.

Affected products

  • Cartalyst Sentry < 2.1.7
  • OpenCFP OpenCFP All versions using Sentry < 2.1.7

Timeline

  • 2016-08-31: disclosed: Bug reported to OpenCFP and patch submitted to Sentry
  • 2016-09-05: patched: Sentry version 2.1.7 released
  • 2024-05-15: advisory: GitHub Advisory published

References

Related threats