First published: Thu Aug 03 2023(Updated: )
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
pip/rdiffweb | <2.8.1 | 2.8.1 |
Ikus-soft Rdiffweb | <2.8.0 | |
<2.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4138 is a vulnerability that allows the allocation of resources without limits or throttling in the GitHub repository ikus060/rdiffweb prior to version 2.8.0.
CVE-2023-4138 has a severity value of 6.5, which is considered medium.
The GitHub repository ikus060/rdiffweb prior to version 2.8.0 and Ikus-soft Rdiffweb up to version 2.8.0 are affected by CVE-2023-4138.
To fix CVE-2023-4138, update the affected software to version 2.8.1.
You can find more information about CVE-2023-4138 at the following references: [Huntr.dev](https://huntr.dev/bounties/1b1fa915-d588-4bb1-9e82-6a6be79befed), [GitHub commit](https://github.com/ikus060/rdiffweb/commit/feef0d7b11d86aed29bf98c21526088117964d85), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-4138).