Raneto v0.17.0 employs weak password complexity requirements
Critical severity
GitHub Reviewed
Published
Aug 5, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Aug 4, 2022
Published to the GitHub Advisory Database
Aug 5, 2022
Reviewed
Aug 11, 2022
Last updated
Jan 31, 2023
Raneto v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks. Version 0.17.1 contains security mitigations for this and other vulnerabilities.
References