PT-2026-73038 · Unknown · Victoriametrics
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VictoriaMetrics versions prior to 1.147.0
Description
An issue exists in the VMAuth Authentication Endpoint within the
requestHandler() function of the app/vmauth/main.go file. A remote attacker can perform a manipulation that leads to improper restriction of excessive authentication attempts. The attack complexity is high and exploitability is considered difficult.Recommendations
Update to version 1.147.0.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Victoriametrics