Description
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-934-1 | radicale security update |
Debian DLA |
DLA-2187-1 | radicale security update |
EUVD |
EUVD-2017-0110 | Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. |
Github GHSA |
GHSA-rpv4-63g3-9x23 | Radicale is vulnerable to timing oracles and simple bruteforce attacks |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T16:34:22.302Z
Reserved: 2017-04-30T00:00:00.000Z
Link: CVE-2017-8342
No data.
Status : Modified
Published: 2017-04-30T15:59:00.153
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-8342
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA