CVE-2022-4723 – rdiffweb
Package
Manager: pip
Name: rdiffweb
Vulnerable Version: >=0 <2.5.5
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00128 pctl0.32962
Details
rdiffweb has no rate limit on resend email feature rdiffweb prior to 2.5.5 has no rate limit on the "resend email feature" while enable or disable 2FA from `/prefs/mfa` endpoint .
Metadata
Created: 2022-12-27T15:30:19Z
Modified: 2024-10-25T21:41:02Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-7q4r-x5qg-mmcp/GHSA-7q4r-x5qg-mmcp.json
CWE IDs: ["CWE-770"]
Alternative ID: GHSA-7q4r-x5qg-mmcp
Finding: F067
Auto approve: 1