sorcery
Provides common authentication needs such as signing in/out, activating by email and resetting password.
Activity
- Latest release
- 9mo ago
- Total releases
- 60
- Cadence
- ~42 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jan 31, 2011
| Version | Released | |
|---|---|---|
0.18.0
minor
|
0.18.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.17.0
minor
|
0.17.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.16.5
patch
|
0.16.5
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.16.4
patch
|
0.16.4
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.16.3
patch
|
0.16.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.16.2
patch
|
0.16.2
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.15.1
patch
|
0.15.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.16.1
patch
|
0.16.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.16.0
minor
|
0.16.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.15.0
minor
|
0.15.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.14.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.14.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.13.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.13.0
minor
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.12.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.12.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.11.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.11.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.10.3
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.10.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.10.2
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.10.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.10.1
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.10.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
0.10.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.10.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
0.9.1
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.9.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.9.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.9.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.8.6
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.6
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
0.8.5
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.5
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.8.4
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.4
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.8.2
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.2
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.8.1
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.8.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.7.13
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.12
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.11
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.10
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.10
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.7.9
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.9
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.7.8
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.8
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.7.7
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.7
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.7.6
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.5
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.3
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.4
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.2
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.1
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.30
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.3
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.21
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.2
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2020-11052
GHSA-jc8m-cxhj-668x
May 07, 2020
Improper Restriction of Excessive Authentication Attempts in Sorcery
8.3
/ 10
High
Network
Low
None
None
Changed
Low
Low
Low
ImpactBrute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. PatchesPatched as of version WorkaroundsCurrently no workarounds, other than monkey patching the authenticate method provided by Sorcery or upgrading to version Affected versions
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.10.0
0.10.1
0.10.2
0.10.3
0.11.0
0.12.0
0.13.0
+ 38 more Show less
0.14.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.5.2
0.5.21
0.5.3
0.5.30
0.6.0
0.6.1
0.7.0
0.7.1
0.7.10
0.7.11
0.7.12
0.7.13
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
0.8.0
0.8.1
0.8.2
0.8.4
0.8.5
0.8.6
0.9.0
0.9.1
Fixed in
0.15.0
References
Updated Jul 08, 2026 · Source: OSV.dev |