Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tuist: Forgot password flow lacks throttling for reset email delivery
Vulnerability Description
Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password reset emails for a known account without server-side throttling. In self-hosted deployments, this can be abused to send large volumes of unwanted email and consume downstream email delivery resources. This vulnerability is fixed in 1.180.10.
CVSS Information
N/A
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
Tuist 安全漏洞
Vulnerability Description
Tuist是Tuist开源的一款Swift应用开发团队协作与性能优化平台。 Tuist 1.180.10之前版本存在安全漏洞,该漏洞源于忘记密码流程缺乏服务器端限速,可能导致未经身份验证的攻击者重复触发密码重置邮件。
CVSS Information
N/A
Vulnerability Type
N/A