Brute Force Affecting alertwise package, versions [,1.0.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Brute Force vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-ALERTWISE-12304066
  • published15 Sept 2025
  • disclosed1 Apr 2025
  • creditUnknown

Introduced: 1 Apr 2025

CVE NOT AVAILABLE CWE-307  (opens in a new tab)

How to fix?

Upgrade alertwise to version 1.0.3 or higher.

Overview

alertwise is a Wagtail based weather warnings composing and dissemination tool

Affected versions of this package are vulnerable to Brute Force due to insufficient login security measures affected version potentially vulnerable to brute-force and credential-stuffing attacks. The issue stems from the lack of rate-limiting, IP tracking, and two-factor authentication in the login process, allowing attackers to attempt logins and potentially compromise user accounts repeatedly.

CVSS Base Scores

version 4.0
version 3.1