CVE-2016-10321: Improper Restriction of Excessive Authentication Attempts
(updated )
web2py does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.
References
Detect and mitigate CVE-2016-10321 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →