Weak password requirements in Kiwi TCMS
CVE-2023-22451
What is CVE-2023-22451?
Kiwi TCMS, an open-source test management system, is susceptible to a vulnerability that allows users to choose easily guessable passwords when registering new accounts or changing their passwords. Versions 11.6 and earlier lack proper validation checks that ensure password strength, potentially compromising user accounts. The flaw is rectified in version 11.7, which enforces stricter password policies to enhance security. These improvements include prohibiting passwords that are overly similar to personal information, mandating a minimum length of 10 characters, disallowing commonly used passwords, and preventing entirely numeric passwords. Administrators have the option to reset passwords if they suspect weak selections have been made by users.
Affected Version(s)
Kiwi <= 11.6
