Sorcery Project maintains a narrowly scoped Ruby authentication library focused on user credential management and access control. The durable signal in the library's disclosures centers on improper restriction of excessive authentication attempts, a class of weakness that recurs across authentication and session-handling implementations. Current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sorcery Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11052CRITICAL In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attac | May 7, 2020 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sorcery Project.
Media articles that mention a CVE ID that affects a product developed by Sorcery Project — matched by CVE ID, not by vendor name.