QID 981221
QID 981221: Python (pip) Security Update for privacyIDEA (GHSA-7qqv-r2q4-jxhm)
privacyIDEA version 2.23.1 and earlier contains a Improper Input Validation vulnerability in token validation api that can result in Denial-of-Service. This attack appear to be exploitable via http request with user=<space>&pass= to /validate/check url. This vulnerability appears to have been fixed in 2.23.2.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7qqv-r2q4-jxhm for updates pertaining to this vulnerability.
Vendor References
- GHSA-7qqv-r2q4-jxhm -
github.com/advisories/GHSA-7qqv-r2q4-jxhm
CVEs related to QID 981221
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7qqv-r2q4-jxhm | privacyIDEA |
|