CVE-2022-3376: rdiffweb allows a new password to be the same as the previous password
(updated )
rdiffweb prior to 2.5.0a4 allows users to set their new password to be the same as the old password during a password reset. Version 2.5.0a4 enforces a password policy in which a new password cannot be the same as the old one.
References
- github.com/advisories/GHSA-7wr6-fj4x-893v
- github.com/ikus060/rdiffweb
- github.com/ikus060/rdiffweb/commit/2ffc2af65c8f8113b06e0b89929c604bcdf844b9
- github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-43157.yaml
- huntr.dev/bounties/a9021e93-6d18-4ac1-98ce-550c4697a4ed
- nvd.nist.gov/vuln/detail/CVE-2022-3376
Detect and mitigate CVE-2022-3376 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →