Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27264 | Fides has a Lack of Brute-Force Protections on Authentication Endpoints |
Github GHSA |
GHSA-7q62-r88r-j5gw | Fides has a Lack of Brute-Force Protections on Authentication Endpoints |
Wed, 10 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ethyca:fides:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ethyca
Ethyca fides |
|
| Vendors & Products |
Ethyca
Ethyca fides |
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lacks specific anti-automation controls designed to protect against brute-force attacks. This could allow attackers to conduct credential testing attacks, such as credential stuffing or password spraying, which poses a risk to accounts with weak or previously compromised passwords. Version 2.69.1 fixes the issue. For organizations with commercial Fides Enterprise licenses, configuring Single Sign-On (SSO) through an OIDC provider (like Azure, Google, or Okta) is an effective workaround. When OIDC SSO is enabled, username/password authentication can be disabled entirely, which eliminates this attack vector. This functionality is not available for Fides Open Source users. | |
| Title | Fides Lacks Brute-Force Protections on Authentication Endpoints | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-09T13:44:06.409Z
Reserved: 2025-08-20T14:30:35.010Z
Link: CVE-2025-57815
Updated: 2025-09-09T13:44:03.180Z
Status : Analyzed
Published: 2025-09-08T22:15:33.520
Modified: 2025-09-10T18:43:41.397
Link: CVE-2025-57815
No data.
OpenCVE Enrichment
Updated: 2025-09-09T21:31:55Z
EUVD
Github GHSA