Radicale before 1.1.2 and 2.0.0rc1 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
{
"nvd_published_at": "2017-04-30T15:59:00Z",
"github_reviewed": true,
"github_reviewed_at": "2023-08-04T21:49:50Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-362"
]
}