
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-3945 is a security vulnerability identified in the GitHub repository kareadita/kavita related to Improper Restriction of Excessive Authentication Attempts. The vulnerability was discovered and disclosed in November 2022 (Red Hat CVE).
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts). The issue was related to how the application handled login attempts and authentication mechanisms, particularly in the way it processed and responded to invalid credentials (NVD CNA).
The vulnerability could potentially allow attackers to perform brute force attacks against user accounts due to the lack of proper authentication attempt restrictions.
The vulnerability was patched through a security update that modified the authentication system. The fix included changes to login response messages, improved error handling for email confirmation, and enhanced security around authentication processes. The patch also implemented better logging of failed authentication attempts (Kavita Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."