Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and potentially DOS the server
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://portal.perforce.com/s/detail/a91PA000001ScY1YAK |
![]() ![]() |
History
Fri, 07 Mar 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 07 Mar 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Username Enumeration in Gliffy | |
References |
|
Wed, 05 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 05 Mar 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Lack of Rate Limiting in Sign-up workflow in Perforce Gliffy prior to version 4.14.0-7 on Gliffy online allows attacker to enumerate valid user emails and potentially DOS the server | |
Weaknesses | CWE-200 CWE-307 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Perforce
Published: 2025-03-05T14:56:53.962Z
Updated: 2025-03-07T04:37:18.431Z
Reserved: 2025-02-26T10:48:12.335Z
Link: CVE-2025-1714

Updated: 2025-03-05T16:20:17.562Z

Status : Received
Published: 2025-03-05T15:15:15.413
Modified: 2025-03-07T05:15:16.233
Link: CVE-2025-1714

No data.