CVE-2024-21500

MEDIUM

caddy-security - Improper Restriction of Excessive Authentication Attempts via 2FA Bypass

Title source: llm
STIX 2.1

Description

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the application’s full multistep 2FA process.

Scores

CVSS v3 4.8
EPSS 0.0053
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (2)
authcrunch/caddy-security
greenpau/caddy-security 0Go
Published Feb 17, 2024
Tracked Since Feb 18, 2026