SB2023021598 - Multiple vulnerabilities in Kiwi
Published: February 15, 2023 Updated: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2023-25171)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to an unspecified flaw in the password reset page when handling password reset requests. A remote attacker can exploit the flaw to compromise confidentiality, integrity, and availability.
2) Improper Restriction of Excessive Authentication Attempts (CVE-ID: CVE-2023-25156)
CWE-ID: CWE-307 - Improper Restriction of Excessive Authentication Attempts
CVSSv4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to gain unauthorized access.
The vulnerability exists due to improper restriction of excessive authentication attempts in the login page when submitting repeated login attempts. An attacker with physical access can submit repeated login attempts to gain unauthorized access.
Remediation
Install update from vendor's website.