All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the application’s full multistep 2FA process.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: snyk
Published: 2024-02-17T05:00:06.899Z
Updated: 2024-03-06T14:09:47.438Z
Reserved: 2023-12-22T12:33:20.119Z
Link: CVE-2024-21500
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-02-17T05:15:10.697
Modified: 2024-02-20T19:50:53.960
Link: CVE-2024-21500
JSON object: View
Redhat Information
No data.
CWE