vantage6 vulnerable to Observable Response Discrepancy
Moderate severity
GitHub Reviewed
Published
Feb 28, 2023
in
vantage6/vantage6
•
Updated Nov 18, 2024
Description
Published to the GitHub Advisory Database
Feb 28, 2023
Reviewed
Feb 28, 2023
Published by the National Vulnerability Database
Mar 1, 2023
Last updated
Nov 18, 2024
Impact
We are incorporating the password policies listed in vantage6/vantage6#59. One measure is that we don't let the user know in case of wrong username/password combination if the username actually exists, to prevent that bots can guess usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily. This way you could still find out which usernames exist.
Patches
Update to 3.8.0+
Workarounds
No
References
vantage6/vantage6#59
For more information
If you have any questions or comments about this advisory:
References