Safety vulnerability ID: 26159
The information on this page was manually curated by our Cybersecurity Intelligence Team.
tiddlyweb before 1.2.18 allowed empty passwords to authenticate.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 2.4.3
An optionally headless, extensible HTTP datastore for tiddlers: bits of stuff.
* SECURITY: Ensure that a password which exists but is the empty string cannot aut…
[This text has been limited. Please create a free account to view the full text.]
Create a free account to access detailed CVSS severity scores and full vulnerability advisories
Create free account