Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21500

Опубликовано: 17 фев. 2024
Источник: nvd
CVSS3: 4.8
CVSS3: 6.5
EPSS Низкий

Описание

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the application’s full multistep 2FA process.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:authcrunch:caddy-security:*:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00048
Низкий

4.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-307
CWE-307

Связанные уязвимости

CVSS3: 4.8
github
почти 2 года назад

Improper Restriction of Excessive Authentication Attempts in github.com/greenpau/caddy-security

EPSS

Процентиль: 15%
0.00048
Низкий

4.8 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-307
CWE-307