CVE-2022-35143

CRITICAL9.8EPSS 0.55%

Raneto v0.17.0 employs weak password complexity requirements

Published: 8/5/2022Modified: 11/8/2023
Also known as:GHSA-7942-2fx8-qhpf

Description

Raneto v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks. Version 0.17.1 contains security mitigations for this and other vulnerabilities.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (9)