Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-wf33-6x33-wcf9: rdiffweb vulnerable to Authentication Bypass by Primary Weakness

In rdiffweb prior to 2.5.5, the username field is not unique to users. This allows exploitation of primary key logic by creating the same name with different combinations & may allow unauthorized access.

ghsa
#web#git#auth

rdiffweb vulnerable to Authentication Bypass by Primary Weakness

High severity GitHub Reviewed Published Dec 27, 2022 • Updated Dec 30, 2022

Related news

CVE-2022-4722: Make username case-insensitive · ikus060/rdiffweb@d1aaa96

Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.