Executive brief
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
Affected products
- PyPI radicale
Junglewise Threat Intelligence
CVE-2017-8342 · Severity: low · CVSS 3.1 · Published 2017-04-30
Technologies: radicale (PyPI). Vendors: PyPI.
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.