PT-2024-39029 · Windmill · Windmill

·

CVE-2024-8462

·

Published

2024-09-05

·

Updated

2024-09-06

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Windmill version 1.380.0
Description: A vulnerability exists in the HTTP Request Handler component, affecting an unknown function of the file backend/windmill-api/src/users.rs. This issue leads to improper restriction of excessive authentication attempts, allowing remote attacks. The complexity of an attack is rather high, and the exploitability is difficult.
Recommendations: For Windmill version 1.380.0, upgrade to version 1.390.1 to address this issue. As a temporary workaround, consider restricting access to the users.rs file or the affected HTTP Request Handler component to minimize the risk of exploitation.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-8462
GHSA-G6Q4-W3J3-JFC4
GO-2024-3118

Affected Products

Windmill