CVE-2023-2531
AzuraCast missing brute force prevention
9.8
CRITICAL
CVSS 3.1
EPSS 0.79%
Description
The request rate limiting feature on the login page of AzuraCast before version 0.18.3 can be bypassed, which could allow an attacker to brute force login credentials.
How to fix CVE-2023-2531
To remediate CVE-2023-2531, upgrade the affected package to a fixed version below.
- Packagist/azuracast/azuracast—upgrade to 0.18.3 or later
Is CVE-2023-2531 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.18.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |