CVE-2024-24769 - CVE House
Back to Database
Status published Low CVE-2024-24769

Vantage6: No limit on emails sent for password/MFA reset

Vulnerability Description

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their MFA token via API routes that send them an email. Currently the number of emails that is sent is not limited. This gives attackers the option to flood someones mailbox with a lot of emails, and would have adverse effects on the SMTP server which may be seen as spam sender. Note resetting the MFA token requires a correct password, so the potential impact for this is very low. Version 5.0.0 fixes the issue. No known workarounds are available.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-24769

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

vantage6
Vulnerable Versions:
< 5.0.0

Timeline

Official Publish: June 17th, 2026
Last Modified: June 18th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)