{"id":"GHSA-r37h-j483-cjjm","summary":"Improper rate limiting in Koel","details":"Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.","aliases":["CVE-2021-33563"],"modified":"2024-12-02T05:55:17.480120Z","published":"2021-06-01T21:38:20Z","database_specific":{"cwe_ids":["CWE-799","CWE-916"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-06-01T20:37:37Z","nvd_published_at":"2021-05-24T23:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33563"},{"type":"WEB","url":"https://github.com/koel/koel/releases/tag/v5.1.4"},{"type":"WEB","url":"https://huntr.dev/bounties/1-other-koel/koel"}],"affected":[{"package":{"name":"phanan/koel","ecosystem":"Packagist","purl":"pkg:composer/phanan/koel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.4"}]}],"versions":["1.0.0-beta","v0.0.0-beta","v1.1.1","v1.1.2","v2.0.0","v2.0.1","v2.0.2","v2.1.0","v2.2.0","v2.2.1","v3.0.0","v3.0.1","v3.1.0","v3.1.1","v3.2.0","v3.3.0","v3.3.1","v3.4.0","v3.4.1","v3.5.0","v3.5.1","v3.5.2","v3.5.3","v3.5.4","v3.5.5","v3.6.0","v3.6.1","v3.6.2","v3.7.0","v3.7.1","v3.7.2","v4.0.0","v4.1.0","v4.1.1","v4.2.0","v4.2.1","v4.2.2","v4.3.0","v4.3.1","v4.4.0","v5.0.0","v5.0.1","v5.0.2","v5.1.0","v5.1.1","v5.1.2","v5.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-r37h-j483-cjjm/GHSA-r37h-j483-cjjm.json"}}],"schema_version":"1.9.0"}