Improper Restriction of Excessive Authentication Attempts in polonel/trudesk

Valid

Reported on

Jul 29th 2021


1)Go to https://docker.trudesk.io/ 2)Enter the username and password 3)Capture the request and start bruteforcing the password

IMPACT:

Account takeover

We have contacted a member of the polonel/trudesk team and are waiting to hear back a year ago
Chris Brame validated this vulnerability 2 months ago
sudheendra17 has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
Chris Brame
2 months ago

Maintainer


This has been fixed in v1.2.2. I will update this report once released.

We have sent a fix follow up to the polonel/trudesk team. We will try again in 7 days. 2 months ago
Chris Brame confirmed that a fix has been merged on 526cef 2 months ago
Chris Brame has been awarded the fix bounty
to join this conversation