Skip to content
GoogleGHSA-c84v-4pjw-4mh2

TurboMeeting: Insecure Password Reset Mechanism

High8.1CVE-2024-38287 · Published Jul 24, 2024

### Summary It was noted that the password reset functionality of the "RHUB TurboMeeting" application resets passwords to a random 8-digit value instead of allowing users to set a new password of their choice. ### Severity High- This vulnerability severely compromises the security of user accounts, especially the default "admin" user. ### Proof of Concept The boolean-based SQL injection referenced [here](https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42v) can be leveraged to exploit and retrieve the admin's hashed password of a recently reset password. This hashed password can then be cracked in under two seconds using hashcat, to an 8-digit value enabling an attacker to authenticate as the admin. ### Further Analysis The password reset functionality should be reconfigured to allow users to set a new password of their choice rather than generating a random 8 character password. Additionally, a strong password policy that requires complex and unique passwords should be enforced. Lastly, multi-factor authentication capabilities should also be implemented to add an additional layer of security prior to authenticating as an admin user. ### Timel...

GitHub advisory

Affected versions

PackageAffectedFixed in
TurboMeeting
Product
all versionsNo fix yet
Details and references

### Summary It was noted that the password reset functionality of the "RHUB TurboMeeting" application resets passwords to a random 8-digit value instead of allowing users to set a new password of their choice. ### Severity High- This vulnerability severely compromises the security of user accounts, especially the default "admin" user. ### Proof of Concept The boolean-based SQL injection referenced [here](https://github.com/google/security-research/security/advisories/GHSA-vx5j-8pgx-v42v) can be leveraged to exploit and retrieve the admin's hashed password of a recently reset password. This hashed password can then be cracked in under two seconds using hashcat, to an 8-digit value enabling an attacker to authenticate as the admin. ### Further Analysis The password reset functionality should be reconfigured to allow users to set a new password of their choice rather than generating a random 8 character password. Additionally, a strong password policy that requires complex and unique passwords should be enforced. Lastly, multi-factor authentication capabilities should also be implemented to add an additional layer of security prior to authenticating as an admin user. ### Timeline **Date reported**: 4/17/2024 **Date fixed**: **Date disclosed**: 7/24/2024

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-640

More Google advisories

All Google
Advisory
Open Broadcaster Software (OBS): Heap Overflow Vulnerability
HighAug 19, 2024
LibRaw: Out of bounds write in LibRaw::sonyParseSR2
MediumAug 14, 2024
TurboMeeting: Post-Authentication Command Injection
High7.2Jul 24, 2024
TurboMeeting: Boolean-based SQL Injection
Critical9.8Jul 24, 2024
Linux Kernel: Vulnerability in the eBPF verifier register limit tracking
MediumJul 16, 2024
Kioxia: Open JTAG Debug Port
High7.3Jul 16, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.