Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Windmill HTTP Request users.rs excessive authentication
Vulnerability Description
A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.390.1 is able to address this issue. The patch is identified as acfe7786152f036f2476f93ab5536571514fa9e3. It is recommended to upgrade the affected component.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
过多认证尝试的限制不恰当
Vulnerability Title
WindMill 安全漏洞
Vulnerability Description
WindMill是Lukasavicus个人开发者的一个免费的开源工具。用于控制 Python 中的作业执行。 WindMill 1.380.0版本存在安全漏洞,该漏洞源于对过度身份验证尝试的限制不当。
CVSS Information
N/A
Vulnerability Type
N/A