CVE-2022-2650: Improper Restriction of Excessive Authentication Attempts in wger-project/wger
Published Nov 24, 2022
·Updated
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
Affected Software
1 affected component
wger wger<2.2
Remediation
Event History
Nov 24, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2650?
CVE-2022-2650 has a medium severity rating due to the risk of unauthorized access from excessive authentication attempts.
2
How do I fix CVE-2022-2650?
To fix CVE-2022-2650, update the wger software to version 2.2 or later, which includes a patch for the vulnerability.
3
What causes CVE-2022-2650?
CVE-2022-2650 is caused by improper restriction of excessive authentication attempts that could lead to brute-force attacks.
4
Who is affected by CVE-2022-2650?
CVE-2022-2650 affects all users of the wger application prior to version 2.2.
5
Is there a workaround for CVE-2022-2650?
A temporary workaround for CVE-2022-2650 is to implement additional rate limiting or CAPTCHA on login attempts.