The CasaOS web application does not have protection against password brute force attacks. An attacker can use a password brute force attack to find and gain full access to the server. This vulnerability allows attackers to get super user-level access over the server.
{ "url": "https://pkg.go.dev/vuln/GO-2024-2614", "review_status": "REVIEWED" }