Critical severity9.8NVD Advisory· Published Apr 10, 2017· Updated Jun 17, 2026
CVE-2016-10321
CVE-2016-10321
Description
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
web2pyPyPI | < 2.14.6 | 2.14.6 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/web2py/web2py/commit/944d8bd8f3c5cf8ae296fc03d149056c65358426nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-gv85-wgxc-vc56ghsaADVISORY
- github.com/web2py/web2py/issues/1585nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-10321ghsaADVISORY
- usn.ubuntu.com/4030-1ghsaWEB
- usn.ubuntu.com/4030-1/nvd
News mentions
0No linked articles in our index yet.