4.11.0
5 years ago
23 days ago
Known vulnerabilities in the vantage6-server package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
vantage6-server is a Vantage6 server Affected versions of this package are vulnerable to Brute Force due to a lack of rate limiting on the password change functionality. An attacker who has gained access to an authenticated session can attempt to brute-force the user's password. They can call the change password route an unlimited number of times, allowing them to systematically guess passwords until they find the correct one and compromise the account. How to fix Brute Force? Upgrade | [,4.11.0rc2) |
vantage6-server is a Vantage6 server Affected versions of this package are vulnerable to Insecure Randomness via the How to fix Insecure Randomness? Upgrade | [,4.11.0rc2) |