CVE Vulnerabilities

CVE-2024-34695

Improper Control of Interaction Frequency

Published: May 14, 2024 | Modified: May 14, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

WOWS Karma is a reputation system for Wargamings World of Warships. A user is able to click multiple times on create on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a users metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.

Weakness

The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.

References