web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Web2py | Web2py | * | 2.14.5 (including) |
Web2py | Ubuntu | artful | * |
Web2py | Ubuntu | precise | * |
Web2py | Ubuntu | trusty | * |
Web2py | Ubuntu | upstream | * |
Web2py | Ubuntu | xenial | * |
Web2py | Ubuntu | yakkety | * |
Web2py | Ubuntu | zesty | * |