Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

rdiffweb allows a new password to be the same as the previous password

GHSA-7wr6-fj4x-893v · CVE-2022-3376 · PYSEC-2022-43157

Published · Modified

Description

rdiffweb prior to 2.5.0a4 allows users to set their new password to be the same as the old password during a password reset. Version 2.5.0a4 enforces a password policy in which a new password cannot be the same as the old one.

Ready to move

Start Securing

Free, no credit card | First findings in minutes