CVE-2022-44023

PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts.
References
Link Resource
https://cve.nstsec.com/cve-2022-44023
https://github.com/pwndoc/pwndoc/issues/382 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:pwndoc_project:pwndoc:*:*:*:*:*:*:*:*

History

02 May 2024, 17:15

Type Values Removed Values Added
References
  • () https://cve.nstsec.com/cve-2022-44023 -

07 Nov 2022, 00:15

Type Values Removed Values Added
Summary PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response timings for authentication attempts. PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response messages for authentication attempts.

31 Oct 2022, 20:01

Type Values Removed Values Added
References (MISC) https://github.com/pwndoc/pwndoc/issues/382 - (MISC) https://github.com/pwndoc/pwndoc/issues/382 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:pwndoc_project:pwndoc:*:*:*:*:*:*:*:*
First Time Pwndoc Project pwndoc
Pwndoc Project
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-307

30 Oct 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-30 00:15

Updated : 2024-05-02 17:15


NVD link : CVE-2022-44023

Mitre link : CVE-2022-44023

CVE.ORG link : CVE-2022-44023


JSON object : View

Products Affected

pwndoc_project

  • pwndoc
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts