4.3
CVSSv2

CVE-2017-8342

Published: 30/04/2017 Updated: 25/04/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Radicale prior to 1.1.2 and 2.x prior to 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

radicale radicale

radicale radicale 2.0.0

Vendor Advisories

Debian Bug report logs - #861514 radicale: CVE-2017-8342: htpasswd authentication vulnerable to timing-based bruteforce attacks Package: radicale; Maintainer for radicale is Jonas Smedegaard <dr@jonesdk>; Source for radicale is src:radicale (PTS, buildd, popcon) Reported by: Jonas Smedegaard <dr@jonesdk> Date: Sat, ...