GHSA-36gx-9q6h-g429MediumCVSS 6.5

vantage6 vulnerable to Observable Response Discrepancy

Published
February 28, 2023
Last Modified
May 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

We are incorporating the password policies listed in https://github.com/vantage6/vantage6/issues/59. One measure is that we don't let the user know in case of wrong username/password combination if the username actually exists, to prevent that bots can guess usernames. However, if a wrong password is entered a number of times, the user account is blocked temporarily. This way you could still find out which usernames exist.

Patches

Update to 3.8.0+

Workarounds

No

References

https://github.com/vantage6/vantage6/issues/59

For more information

If you have any questions or comments about this advisory:

🎯 Affected products1

  • pip/vantage6:< 3.8.0

🔗 References (8)