Lucene search

K
osvGoogleOSV:GHSA-GV85-WGXC-VC56
HistoryMay 14, 2022 - 12:57 a.m.

web2py is vulnerable to password brute-force attack

2022-05-1400:57:47
Google
osv.dev
2

0.008 Low

EPSS

Percentile

82.0%

web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.

CPENameOperatorVersion
web2pyeq2.1.1
web2pyeq1.98.2
web2pyeq1.96.4

0.008 Low

EPSS

Percentile

82.0%