Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://huntr.dev/bounties/474d3b39-1882-4d2c-b8f7-ff9f68f14cee | patch exploit third party advisory issue tracking |
https://github.com/linagora/twake/commit/0770da3b184b5d5e71fee8251a5847a04c7cb9bc | patch |