
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2022-3371) affects the GitHub repository ikus060/rdiffweb prior to version 2.5, involving an Allocation of Resources Without Limits or Throttling issue (Red Hat CVE).
The vulnerability relates to insufficient validation of user input fields, specifically affecting the user's fullname and token name field lengths. A fix was implemented to add length validation constraints, limiting these fields to a maximum of 256 characters (GitHub Commit).
The vulnerability could potentially lead to resource allocation issues in the application when processing user input fields without proper length restrictions.
The issue has been resolved in rdiffweb version 2.5 and later by implementing length validation constraints that limit the fullname and token name fields to 256 characters (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."