Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 PyPI

rdiffweb contains Weak Password Requirements

GHSA-mp5p-g2jv-r8qw · CVE-2022-3179 · PYSEC-2022-272

Published · Modified

Description

rdiffweb version 2.4.1 has no password policy or password checking, which could make users vulnerable to brute force password guessing attacks. Version 2.4.2 enforces minimum and maximum password lengths.

Ready to move

Start Securing

Free, no credit card | First findings in minutes