Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 PyPI

rdiffweb vulnerable to password complexity bypass leading to weak passwords

GHSA-8wxf-c45w-g66g · CVE-2022-3326 · PYSEC-2022-297

Published · Modified

Description

ikus060/rdiffweb prior to 2.4.9 allows a user to set there password to all spaces. While rdiffweb has a password policy requiring passwords to be between 8 and 128 characters, it does not validate the password entropy, allowing users to bypass password complexity requirements with weak passwords. This issue has been fixed in version 2.4.9. No workarounds are known to exist.

Ready to move

Start Securing

Free, no credit card | First findings in minutes