Radicale before 1.1.2 and 2.0.0rc1 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
{ "nvd_published_at": "2017-04-30T15:59:00Z", "cwe_ids": [ "CWE-362" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-08-04T21:49:50Z" }