MEDIUM 5.3 PyPI
rdiffweb allows a new password to be the same as the previous password
GHSA-7wr6-fj4x-893v · CVE-2022-3376 · PYSEC-2022-43157
Published · Modified
Description
rdiffweb prior to 2.5.0a4 allows users to set their new password to be the same as the old password during a password reset. Version 2.5.0a4 enforces a password policy in which a new password cannot be the same as the old one.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-3376
- WEB https://github.com/ikus060/rdiffweb/commit/2ffc2af65c8f8113b06e0b89929c604bcdf844b9
- PACKAGE https://github.com/ikus060/rdiffweb
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-43157.yaml
- WEB https://huntr.dev/bounties/a9021e93-6d18-4ac1-98ce-550c4697a4ed
Ready to move
Start Securing
Free, no credit card | First findings in minutes