django-allauth is vulnerable to Improper Restriction of Excessive Authentication Attempts
42
Medium Risk
Affected versions of this package are vulnerable to a bruteforce attack due to the lack of enforcement of the 'settings.ACCOUNT_EMAIL_VERIFICATION_BY_CODE_MAX_ATTEMPTS' parameter. This issue arises because the number of attempts allowed for email account verification is not properly limited, allowing attackers to try many verification codes in a short amount of time.
You are affected if you are using a version that falls within the vulnerable range.
django-allauth is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 0.63.0 - 65.1.0.
Upgrade the django-allauth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant