Skip to content

Improper Restriction of Excessive Authentication Attempts

Moderate
Abraxas-Bot published GHSA-2xfx-whr5-qg88 Mar 9, 2023

Package

VOTING IAM (Abraxas Apps Platform)

Affected versions

< 1.22.3

Patched versions

1.22.3

Description

Short Description

The attacker can execute multiple authentication attempts without being locked out.

Reporting Date

  1. August 2022

Details

The attacker can execute a brute force attack against the authentication endpoint to figure out the victim's credentials. The victim's account is not locked out due a missing rate limit in the backend when attempting multiple invalid authentication requests.

Impact

Low

References

  • Bug Bounty ID: 5443fef4 (Private)
  • Internal ID: SEC-742

❤ Thanks to

Hassan Jawaid for reporting the authentication rate limit vulnerability.

Severity

Moderate
4.2
/ 10

CVSS base metrics

Attack vector
Adjacent
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CVE ID

No known CVE

Weaknesses