Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://huntr.dev/bounties/5233f76f-016b-4c65-b019-2c5d27802a1b | exploit third party advisory patch |
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53 | third party advisory patch |