Headline
GHSA-9g3v-v24q-jj5p: rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks
rdiffweb prior to 2.5.0a4 does not have a rate limit to prevent attackers attempting brute force attacks to guess passwords. Version 2.5.0a4 limits the number of incorrect password attempts.
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2022-3273
rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks
Low severity GitHub Reviewed Published Oct 6, 2022 • Updated Oct 6, 2022
Package
pip rdiffweb (pip)
Affected versions
< 2.5.0
Description
Related news
CVE-2022-3273: Limit incorrect attempts to change the user's password to prevent bru… · ikus060/rdiffweb@b5e3bb0
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.