Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-9g3v-v24q-jj5p: rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks

rdiffweb prior to 2.5.0a4 does not have a rate limit to prevent attackers attempting brute force attacks to guess passwords. Version 2.5.0a4 limits the number of incorrect password attempts.

ghsa
#web#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-3273

rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks

Low severity GitHub Reviewed Published Oct 6, 2022 • Updated Oct 6, 2022

Package

pip rdiffweb (pip)

Affected versions

< 2.5.0

Description

Related news

CVE-2022-3273: Limit incorrect attempts to change the user's password to prevent bru… · ikus060/rdiffweb@b5e3bb0

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.