PT-2021-23146 · Elabftw · Elabftw

Krastanoel

·

Published

2021-10-22

·

Updated

2021-10-28

·

CVE-2021-41171

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eLabFTW versions prior to 4.1.0
Description The issue allows attackers to bypass a brute-force protection mechanism by using many different forged PHPSESSID values in the HTTP Cookie header. This has been addressed by implementing brute force login protection, as recommended by Owasp with Device Cookies, which will effectively thwart any brute-force attempts at guessing passwords.
Recommendations For versions prior to 4.1.0, the only correct way to address this is to upgrade to version 4.1.0. Adding rate limitation upstream of the eLabFTW service is a valid option, with or without upgrading.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41171
GHSA-Q67H-5PC3-G6JV

Affected Products

Elabftw