CRITICAL9.8
GHSA-7942-2fx8-qhpf
Raneto v0.17.0 employs weak password complexity requirements
Quick fix
GHSA-7942-2fx8-qhpf — raneto: upgrade to the fixed version with the command below.
npm install raneto@0.17.1Details
Raneto v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks. Version 0.17.1 contains security mitigations for this and other vulnerabilities.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-35143[ADVISORY]
- https://github.com/ryanlelek/Raneto/pull/370[WEB]
- https://github.com/ryanlelek/Raneto/commit/55e442c9bc67b845094e14ceb228e95c639595be[WEB]
- https://cwe.mitre.org/data/definitions/521.html[WEB]
- https://gainsec.com/2022/08/04/cve-2022-35142-cve-2022-35143-cve-2022-35144[WEB]
- https://github.com/gilbitron/Raneto/releases[WEB]
- https://github.com/ryanlelek/Raneto[PACKAGE]
- https://github.com/ryanlelek/Raneto/releases/tag/0.17.1[WEB]
- http://raneto.com[WEB]