Описание
Drupal Open Social allows Functionality Misuse
The distribution didn't validate the flood control limits on the password reset form correctly resulting in a potential attacker flooding the password reset which could result in a Denial of Service. Fortunately the message does not disclose any information to the attacker.
Пакеты
goalgorilla/open_social
< 12.3.8
12.3.8
goalgorilla/open_social
>= 12.4.0, < 12.4.5
12.4.5
goalgorilla/open_social
>= 13.0.0-alpha1, < 13.0.0-alpha11
13.0.0-alpha11
Связанные уязвимости
Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.
Уязвимость модуля Open Social CMS-системы Drupal, связанная с недостаточным контролем за частотой взаимодействий, позволяющая нарушителю вызвать отказ в обслуживании