Headline
GHSA-7wr6-fj4x-893v: rdiffweb allows a new password to be the same as the previous password
rdiffweb prior to 2.5.0a4 allows users to set their new password to be the same as the old password during a password reset. Version 2.5.0a4 enforces a password policy in which a new password cannot be the same as the old one.
rdiffweb allows a new password to be the same as the previous password
Low severity GitHub Reviewed Published Oct 6, 2022 • Updated Oct 6, 2022
Related news
CVE-2022-3376: Enforce password policy new password cannot be set as new password · ikus060/rdiffweb@2ffc2af
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.