logo

CVE-2022-4723 rdiffweb

Package

Manager: pip
Name: rdiffweb
Vulnerable Version: >=0 <2.5.5

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00128 pctl0.32962

Details

rdiffweb has no rate limit on resend email feature rdiffweb prior to 2.5.5 has no rate limit on the "resend email feature" while enable or disable 2FA from `/prefs/mfa` endpoint .

Metadata

Created: 2022-12-27T15:30:19Z
Modified: 2024-10-25T21:41:02Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-7q4r-x5qg-mmcp/GHSA-7q4r-x5qg-mmcp.json
CWE IDs: ["CWE-770"]
Alternative ID: GHSA-7q4r-x5qg-mmcp
Finding: F067
Auto approve: 1