Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-934-1 radicale security update
Debian DLA Debian DLA DLA-2187-1 radicale security update
EUVD EUVD EUVD-2017-0110 Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
Github GHSA Github GHSA GHSA-rpv4-63g3-9x23 Radicale is vulnerable to timing oracles and simple bruteforce attacks
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T16:34:22.302Z

Reserved: 2017-04-30T00:00:00

Link: CVE-2017-8342

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-04-30T15:59:00.153

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-8342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.