CVE-2025-43863: vantage6 lacks brute-force protection on change password functionality
If attacker gets access to an authenticated session, they can try to brute-force the user password by using the change password functionality: they can call that route infinitely which will return the message that password is wrong until it is correct
References
Code Behaviors & Features
Detect and mitigate CVE-2025-43863 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →