漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Windmill HTTP Request users.rs excessive authentication
Vulnerability Description
A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.390.1 is able to address this issue. The patch is identified as acfe7786152f036f2476f93ab5536571514fa9e3. It is recommended to upgrade the affected component.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
过多认证尝试的限制不恰当
Vulnerability Title
WindMill 安全漏洞
Vulnerability Description
WindMill是Lukasavicus个人开发者的一个免费的开源工具。用于控制 Python 中的作业执行。 WindMill 1.380.0版本存在安全漏洞,该漏洞源于对过度身份验证尝试的限制不当。
CVSS Information
N/A
Vulnerability Type
N/A