Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.
Users should upgrade to v12.0 or later.
Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.
{
"github_reviewed_at": "2023-02-15T18:10:54Z",
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-307"
],
"nvd_published_at": "2023-02-15T15:15:00Z"
}