{"id":"GHSA-mp5p-g2jv-r8qw","summary":"rdiffweb contains Weak Password Requirements","details":"rdiffweb version 2.4.1 has no password policy or password checking, which could make users vulnerable to brute force password guessing attacks. Version 2.4.2 enforces minimum and maximum password lengths.","aliases":["CVE-2022-3179","PYSEC-2022-272"],"modified":"2024-10-25T21:32:14Z","published":"2022-09-14T00:00:43Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-09-15T03:24:48Z","nvd_published_at":"2022-09-13T17:15:00Z","cwe_ids":["CWE-521"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3179"},{"type":"WEB","url":"https://github.com/ikus060/rdiffweb/commit/233befc33bdc45d4838c773d5aed4408720504c5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mp5p-g2jv-r8qw"},{"type":"PACKAGE","url":"https://github.com/ikus060/rdiffweb"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-272.yaml"},{"type":"WEB","url":"https://huntr.dev/bounties/58eae29e-3619-449d-9bba-fdcbabcba5fe"}],"affected":[{"package":{"name":"rdiffweb","ecosystem":"PyPI","purl":"pkg:pypi/rdiffweb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.1"},{"fixed":"2.4.2"}]}],"versions":["2.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-mp5p-g2jv-r8qw/GHSA-mp5p-g2jv-r8qw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}