vendor:
Litespeed Cache
by:
Gonzales
6.1
CVSS
HIGH
Authentication Bypass
284
CWE
Product Name: Litespeed Cache
Affected Version From: 6.5.0.1
Affected Version To: 6.5.0.1
Patch Exists: NO
Related CWE: CVE-2024-44000
CPE: a:litespeedtech:litespeed_cache:6.5.0.1
Platforms Tested: macOS M2 Pro
2024
Litespeed Cache 6.5.0.1 – Authentication Bypass
The Litespeed Cache version 6.5.0.1 allows unauthorized access to user accounts due to improper validation of user cookies. An attacker can exploit this vulnerability to impersonate legitimate users and gain unauthorized access to their accounts.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Litespeed Cache that addresses this authentication bypass issue.