alertwise@1.0.0 vulnerabilities

Wagtail based weather warnings composing and dissemination tool

  • latest version

    1.1.5

  • latest non vulnerable version

  • first published

    9 months ago

  • latest version published

    3 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the alertwise package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Brute Force

    alertwise is a Wagtail based weather warnings composing and dissemination tool

    Affected versions of this package are vulnerable to Brute Force due to insufficient login security measures affected version potentially vulnerable to brute-force and credential-stuffing attacks. The issue stems from the lack of rate-limiting, IP tracking, and two-factor authentication in the login process, allowing attackers to attempt logins and potentially compromise user accounts repeatedly.

    How to fix Brute Force?

    Upgrade alertwise to version 1.0.3 or higher.

    [,1.0.3)