Skip to main content

Improper Restriction of Excessive Authentication Attempts

CVE-2025-57815

Severity Low
Score 1.7/10

Summary

Fides is an open-source privacy engineering platform. Prior to version 2.69.1b2, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lacks specific anti-automation controls designed to protect against Brute-Force Attacks. This could allow attackers to conduct Credential Testing Attacks, such as Credential Stuffing or Password Spraying, which poses a risk to accounts with weak or previously compromised passwords. For organizations with commercial Fides Enterprise licenses, configuring Single Sign-On (SSO) through an OIDC provider (like Azure, Google, or Okta) is an effective workaround. When OIDC SSO is enabled, username/password authentication can be disabled entirely, which eliminates this attack vector. This functionality is not available for Fides Open Source users.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-307 - Improper Restriction of Excessive Authentication Attempts

The software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.

Advisory Timeline

  • Published