rdiffweb@2.6.1 vulnerabilities

A web interface to rdiff-backup repositories.

Direct Vulnerabilities

Known vulnerabilities in the rdiffweb package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Allocation of Resources Without Limits or Throttling

rdiffweb is an A web interface to rdiff-backup repositories.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling by exploiting the lack of resource allocation limits or throttling when creating access tokens.

How to fix Allocation of Resources Without Limits or Throttling?

Upgrade rdiffweb to version 2.8.4 or higher.

[,2.8.4)
  • M
Allocation of Resources Without Limits or Throttling

rdiffweb is an A web interface to rdiff-backup repositories.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling. There is no rate limit on the send report feature on the https://rdiffweb-dev.ikus-soft.com/prefs/notification endpoint, which allows an attacker to spam the victim's mailbox.

How to fix Allocation of Resources Without Limits or Throttling?

Upgrade rdiffweb to version 2.8.1 or higher.

[,2.8.1)