Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://github.com/ikus060/rdiffweb/commit/f2a32f2a9f3fb8be1a9432ac3d81d3aacdb13095 | third party advisory patch |
https://huntr.dev/bounties/5340c2f6-0252-40f6-8929-cca5d64958a5 | third party advisory exploit |