The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-08T00:28:04

Updated: 2024-08-03T10:21:33.223Z

Reserved: 2022-08-01T00:00:00

Link: CVE-2022-37145

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-09-08T01:15:07.450

Modified: 2022-09-13T18:23:24.013

Link: CVE-2022-37145

cve-icon Redhat

No data.