Robuta

https://rdiffweb.org/ Rdiffweb: Modern Web UI for rdiff-backup Restoration Rdiffweb provides an intuitive web UI for rdiff-backup repositories. Restore files from any point in time, manage users, monitor backup health, and automate... modern webrdiffwebuibackuprestoration https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3298/ rdiffweb vulnerable to potential DoS via memory consumption | GitLab Advisory Database (GLAD) CVE-2022-3298 rdiffweb vulnerable to potential DoS via memory consumption: rdiffweb prior to 2.4.8 is vulnerable to a potential Dos attack via an unlimited... https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-4314/ Improper Privilege Management in rdiffweb | GitLab Advisory Database (GLAD) CVE-2022-4314 Improper Privilege Management in rdiffweb: Unauthorized access to settings update, logs , history, delete etc in GitHub repository... privilege managementimproperrdiffwebgitlabadvisory https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3362/ rdiffweb vulnerable to Insufficient Session Expiration | GitLab Advisory Database (GLAD) CVE-2022-3362 rdiffweb vulnerable to Insufficient Session Expiration: Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0. rdiffwebvulnerableinsufficientsessionexpiration https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3290/ rdiffweb's unlimited username field length can lead to DoS | GitLab Advisory Database (GLAD) CVE-2022-3290 rdiffweb's unlimited username field length can lead to DoS: rdiffweb prior to 2.4.8 is vulnerable to a potential Dos attack via an unlimited... https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3221/ rdiffweb CSRF vulnerability in profile's SSH keys can lead to unauthorized access | GitLab Advisory... CVE-2022-3221 rdiffweb CSRF vulnerability in profile's SSH keys can lead to unauthorized access: rdiffweb prior to 2.4.3 is vulnerable to Cross-Site Request... https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-4721/ rdiffweb vulnerable to Special Element Injection | GitLab Advisory Database (GLAD) CVE-2022-4721 rdiffweb vulnerable to Special Element Injection: In rdiffweb prior to 2.5.5, lack of sanitisation of characters in SSH key name could allow... special elementrdiffwebvulnerableinjectiongitlab https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3327/ Rdiffweb is missing authentication for critical function | GitLab Advisory Database (GLAD) CVE-2022-3327 Rdiffweb is missing authentication for critical function: Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb... rdiffwebmissingauthentication https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-4646/ rdiffweb vulnerable to Cross-Site Request Forgery | GitLab Advisory Database (GLAD) CVE-2022-4646 rdiffweb vulnerable to Cross-Site Request Forgery: rdiffweb prior to version 2.5.4 is vulnerable to Cross-Site Request Forgery (CSRF). cross site request forgeryrdiffwebvulnerable https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-4722/ rdiffweb vulnerable to Authentication Bypass by Primary Weakness | GitLab Advisory Database (GLAD) CVE-2022-4722 rdiffweb vulnerable to Authentication Bypass by Primary Weakness: In rdiffweb prior to 2.5.5, the username field is not unique to users. This... authentication bypass https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3364/ rdiffweb's unlimited length Fullname field can lead to DoS | GitLab Advisory Database (GLAD) CVE-2022-3364 rdiffweb's unlimited length Fullname field can lead to DoS: rdiffweb prior to 2.5.0a3 does not validate email length, allowing users to insert an... https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3376/ rdiffweb allows a new password to be the same as the previous password | GitLab Advisory Database... CVE-2022-3376 rdiffweb allows a new password to be the same as the previous password: rdiffweb prior to 2.5.0a4 allows users to set their new password to be... https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3273/ rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks |... CVE-2022-3273 rdiffweb does not have a rate limit on incorrect password attempts to prevent brute force attacks: rdiffweb prior to 2.5.0a4 does not have a rate... https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3439/ Missing rate limit on rdiffweb | GitLab Advisory Database (GLAD) CVE-2022-3439 Missing rate limit on rdiffweb: Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. rate limitmissingrdiffwebgitlabadvisory https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3371/ rdiffweb's lack of token name length limit can result in DoS or memory corruption | GitLab Advisory... CVE-2022-3371 rdiffweb's lack of token name length limit can result in DoS or memory corruption: rdiffweb prior to 2.5.0a3 is vulnerable to Allocation of... https://advisories.gitlab.com/pypi/rdiffweb/CVE-2022-3179/ rdiffweb contains Weak Password Requirements | GitLab Advisory Database (GLAD) CVE-2022-3179 rdiffweb contains Weak Password Requirements: rdiffweb version 2.4.1 has no password policy or password checking, which could make users... password requirementsrdiffwebcontainsweakgitlab