Weak Password Requirements in janeczku/calibre-web
CVE-2023-2106

9.8CRITICAL

Key Information:

Vendor
Janeczku
Vendor
CVE Published:
15 April 2023

Summary

The Calibre-Web application developed by Janeczku exhibits insecure password practices that can lead to unauthorized access. Before version 0.6.20, the system allowed users to set weak passwords, significantly increasing the risk of credential theft and account compromise. This vulnerability underscores the need for stringent password policies to safeguard user data and maintain system integrity. Users are advised to update to the latest version and reinforce their security measures.

Affected Version(s)

janeczku/calibre-web < 0.6.20

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.