QID 995983
Date Published: 2023-11-20
QID 995983: PHP (Composer) Security Update for librenms/librenms (GHSA-rq42-58qf-v3qx)
Application is using two login methods and one of them is using GET request for authentication. There is no rate limiting security feature at GET request or backend is not validating that.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rq42-58qf-v3qx for updates and patch information.
Vendor References
- GHSA-rq42-58qf-v3qx -
github.com/advisories/GHSA-rq42-58qf-v3qx
CVEs related to QID 995983
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rq42-58qf-v3qx | librenms/librenms |
|