Launch Week Day 1: Announcing Security Design Review
HIGH 7.2 PyPI

rdiffweb vulnerable to Authentication Bypass by Primary Weakness

GHSA-wf33-6x33-wcf9 · CVE-2022-4722 · PYSEC-2022-43008

Published · Modified

Description

In rdiffweb prior to 2.5.5, the username field is not unique to users. This allows exploitation of primary key logic by creating the same name with different combinations & may allow unauthorized access.

Ready to move

Start Securing

Free, no credit card | First findings in minutes