CVE-2022-4723: rdiffweb has no rate limit on resend email feature
(updated )
rdiffweb prior to 2.5.5 has no rate limit on the “resend email feature” while enable or disable 2FA from /prefs/mfa
endpoint .
References
- github.com/advisories/GHSA-7q4r-x5qg-mmcp
- github.com/ikus060/rdiffweb
- github.com/ikus060/rdiffweb/commit/6e9ee210548f6d3210704cac302cfc7cdb239765
- github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-43009.yaml
- huntr.dev/bounties/9369681b-8bfc-4146-a54c-c5108442d92c
- nvd.nist.gov/vuln/detail/CVE-2022-4723
Detect and mitigate CVE-2022-4723 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →