CVE-2023-2531: Improper Restriction of Excessive Authentication Attempts in azuracast/azuracast
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
Other sources
The request rate limiting feature on the login page of AzuraCast before version 0.18.3 can be bypassed, which could allow an attacker to brute force login credentials.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2531?
CVE-2023-2531 has a high severity due to the potential for attackers to bypass request rate limiting and brute force login credentials.
How do I fix CVE-2023-2531?
To fix CVE-2023-2531, upgrade AzuraCast to version 0.18.3 or later.
What type of vulnerability is CVE-2023-2531?
CVE-2023-2531 is categorized as an Improper Restriction of Excessive Authentication Attempts vulnerability.
What software is affected by CVE-2023-2531?
CVE-2023-2531 affects AzuraCast versions prior to 0.18.3.
Can CVE-2023-2531 be exploited remotely?
Yes, CVE-2023-2531 can be exploited remotely since it involves the login page of the AzuraCast application.