Improper resource allocation In rdiffweb
Description
rdiffweb has no rate limit on resend email feature
rdiffweb prior to 2.5.5 has no rate limit on the "resend email feature" while enable or disable 2FA from /prefs/mfa endpoint .
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.5.5 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.