In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade roundup
to version 2.1.0b1 or higher.
roundup is a simple-to-use and -install issue-tracking system with command-line, web and e-mail interfaces.
Affected versions of this package are vulnerable to Timing Attack via the verifyLogin
function, because it doesn't run a password check when the user doesn't exist, which might expose valid usernames