calibreweb@0.6.18 vulnerabilities

Web app for browsing, reading and downloading eBooks stored in a Calibre database.

Direct Vulnerabilities

Known vulnerabilities in the calibreweb package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Weak Password Requirements

calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database.

Affected versions of this package are vulnerable to Weak Password Requirements due to missing rate limits in the login functionality.

How to fix Weak Password Requirements?

Upgrade calibreweb to version 0.6.20 or higher.

[,0.6.20)
  • H
Brute Force

calibreweb is a Web app for browsing, reading and downloading eBooks stored in a Calibre database.

Affected versions of this package are vulnerable to Brute Force due to missing rate limiting in login form.

How to fix Brute Force?

Upgrade calibreweb to version 0.6.20 or higher.

[,0.6.20)