Логотип exploitDog
bind:CVE-2020-11052
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11052

Количество 2

Количество 2

nvd логотип

CVE-2020-11052

почти 6 лет назад

In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired, protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. This has been patched in 0.15.0.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-jc8m-cxhj-668x

почти 6 лет назад

Improper Restriction of Excessive Authentication Attempts in Sorcery

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-11052

In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired, protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. This has been patched in 0.15.0.

CVSS3: 8.3
1%
Низкий
почти 6 лет назад
github логотип
GHSA-jc8m-cxhj-668x

Improper Restriction of Excessive Authentication Attempts in Sorcery

CVSS3: 8.3
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу