Launch Week Day 1: Announcing Security Design Review
HIGH 7.3 PyPI

rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks

GHSA-9g3v-v24q-jj5p · CVE-2022-3273 · PYSEC-2022-43156

Published · Modified

Description

rdiffweb prior to 2.5.0a4 does not have a rate limit to prevent attackers attempting brute force attacks to guess passwords. Version 2.5.0a4 limits the number of incorrect password attempts.

Ready to move

Start Securing

Free, no credit card | First findings in minutes