1.1.5
9 months ago
3 months ago
Known vulnerabilities in the alertwise package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
alertwise is a Wagtail based weather warnings composing and dissemination tool Affected versions of this package are vulnerable to Brute Force due to insufficient login security measures affected version potentially vulnerable to brute-force and credential-stuffing attacks. The issue stems from the lack of rate-limiting, IP tracking, and two-factor authentication in the login process, allowing attackers to attempt logins and potentially compromise user accounts repeatedly. How to fix Brute Force? Upgrade | [,1.0.3) |