SB2023021598 - Multiple vulnerabilities in Kiwi



SB2023021598 - Multiple vulnerabilities in Kiwi

Published: February 15, 2023 Updated: September 18, 2026

Security Bulletin ID SB2023021598
CSH Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Resource exhaustion (CVE-ID: CVE-2023-25171)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to an unspecified flaw in the password reset page when handling password reset requests. A remote attacker can exploit the flaw to compromise confidentiality, integrity, and availability.


2) Improper Restriction of Excessive Authentication Attempts (CVE-ID: CVE-2023-25156)

CWE-ID: CWE-307 - Improper Restriction of Excessive Authentication Attempts

CVSSv4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to gain unauthorized access.

The vulnerability exists due to improper restriction of excessive authentication attempts in the login page when submitting repeated login attempts. An attacker with physical access can submit repeated login attempts to gain unauthorized access.


Remediation

Install update from vendor's website.