PT-2022-25125 · Kareadita · Kavita

Published

2022-11-14

·

Updated

2023-06-29

·

CVE-2022-3993

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions kareadita/kavita versions prior to 0.6.0.3
Description The issue is related to improper restriction of excessive authentication attempts, which can lead to authentication bypass. This allows attackers to exploit the weakness in the authentication process.
Recommendations For versions prior to 0.6.0.3, update to version 0.6.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the authentication module to minimize the risk of exploitation.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2022-3993

Affected Products

Kavita