Weak credential policy In rdiffweb
Description
rdiffweb contains Weak Password Requirements rdiffweb version 2.4.1 has no password policy or password checking, which could make users vulnerable to brute force password guessing attacks. Version 2.4.2 enforces minimum and maximum password lengths.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.4.2 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.