9.8
CVE-2020-11052
- EPSS 1.6%
- Veröffentlicht 07.05.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:56:41
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Improper Restriction of Excessive Authentication Attempts in Sorcery
In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired, protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. This has been patched in 0.15.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sorcery Project ≫ Sorcery SwPlatformruby Version < 0.15.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.6% | 0.726 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| security-advisories@github.com | 8.3 | 3.9 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
https://github.com/Sorcery/sorcery/commit/0f116d223826895a73b12492f17486e5d54ab7a7
https://github.com/Sorcery/sorcery/issues/231
https://github.com/Sorcery/sorcery/pull/235
https://github.com/Sorcery/sorcery/security/advisories/GHSA-jc8m-cxhj-668x