CVE-2023-25156
published 2023-02-15CVE-2023-25156: Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.90%
55.2th percentile
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround, users may install and configure a rate-limiting proxy in front of Kiwi TCMS.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| kiwitcms | kiwi | >= 12.0 < 12.0 | 12.0 |
| kiwitcms | kiwi_tcms | < 12.0 | 12.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
No protection against brute-force attacks on login page
osv·2023-02-15
CVE-2023-25156 [HIGH] No protection against brute-force attacks on login page
No protection against brute-force attacks on login page
### Impact
Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.
### Patches
Users should upgrade to v12.0 or later.
### Workarounds
Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.
### References
[Disclosed by spyata](https://huntr.dev/bounties/2b1a9be9-45e9-490b-8de0-26a492e79795/)
GHSA
No protection against brute-force attacks on login page
ghsa·2023-02-15
CVE-2023-25156 [HIGH] CWE-307 No protection against brute-force attacks on login page
No protection against brute-force attacks on login page
### Impact
Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.
### Patches
Users should upgrade to v12.0 or later.
### Workarounds
Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.
### References
[Disclosed by spyata](https://huntr.dev/bounties/2b1a9be9-45e9-490b-8de0-26a492e79795/)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kiwitcms/Kiwi/commit/0ed213fa0ddb7a6dc77e3c3b99e8fc90ccdaf46fhttps://github.com/kiwitcms/Kiwi/security/advisories/GHSA-7968-h4m4-ghm9https://huntr.dev/bounties/2b1a9be9-45e9-490b-8de0-26a492e79795/https://kiwitcms.org/blog/kiwi-tcms-team/2023/02/15/kiwi-tcms-120/https://github.com/kiwitcms/Kiwi/commit/0ed213fa0ddb7a6dc77e3c3b99e8fc90ccdaf46fhttps://github.com/kiwitcms/Kiwi/security/advisories/GHSA-7968-h4m4-ghm9https://huntr.dev/bounties/2b1a9be9-45e9-490b-8de0-26a492e79795/https://kiwitcms.org/blog/kiwi-tcms-team/2023/02/15/kiwi-tcms-120/
2023-02-15
Published