Headline
GHSA-wf33-6x33-wcf9: rdiffweb vulnerable to Authentication Bypass by Primary Weakness
In rdiffweb prior to 2.5.5, the username field is not unique to users. This allows exploitation of primary key logic by creating the same name with different combinations & may allow unauthorized access.
rdiffweb vulnerable to Authentication Bypass by Primary Weakness
High severity GitHub Reviewed Published Dec 27, 2022 • Updated Dec 30, 2022
Related news
CVE-2022-4722: Make username case-insensitive · ikus060/rdiffweb@d1aaa96
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.