vendor:
Bludit
by:
noraj (Alexandre ZANNI)
9.8
CVSS
CRITICAL
Authentication Bruteforce Mitigation Bypass
287
CWE
Product Name: Bludit
Affected Version From: <= 3.9.2
Affected Version To: <= 3.9.2
Patch Exists: YES
Related CWE: CVE-2019-17240
CPE: a:bludit:bludit:3.9.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Bludit Version 3.9.2
2020
Bludit 3.9.2 – Authentication Bruteforce Mitigation Bypass
Bludit version 3.9.2 is vulnerable to an authentication bruteforce mitigation bypass. This vulnerability allows an attacker to bypass the bruteforce protection mechanism of the application and brute-force the login page. The vulnerability is due to the application not properly validating the X-Forwarded-For header. An attacker can send a crafted X-Forwarded-For header with a valid username and an invalid password to bypass the bruteforce protection mechanism.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of Bludit.