django-allauth is vulnerable to Improper Restriction of Excessive Authentication Attempts
20
Low Risk
Affected versions of this package are vulnerable to a rate-limiting bypass due to improper handling of failed login attempts. It allows an attacker to reset the rate limit for an IP address by performing a successful login, effectively bypassing brute-force protection. An attacker could exploit this by first making multiple failed login attempts, then using a known or guessed password to log in successfully, clearing the rate limit, and allowing further brute-force attempts.
You are affected if you are using a version that falls within the vulnerable range.
django-allauth is vulnerable to Improper Restriction of Excessive Authentication Attempts in versions 0.56.0 - 65.8.0.
Upgrade the django-allauth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant