All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the application’s full multistep 2FA process.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Apr 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Authcrunch
Authcrunch caddy-security |
|
CPEs | cpe:2.3:a:authcrunch:caddy-security:*:*:*:*:*:*:*:* | |
Vendors & Products |
Authcrunch
Authcrunch caddy-security |
Wed, 20 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-12-05T20:33:44.652Z
Reserved: 2023-12-22T12:33:20.119Z
Link: CVE-2024-21500

Updated: 2024-08-01T22:20:41.007Z

Status : Analyzed
Published: 2024-02-17T05:15:10.697
Modified: 2025-04-03T16:12:19.953
Link: CVE-2024-21500

No data.