Описание
Silverstripe Brute force bypass on default admin
Default Administrator accounts were not subject to the same brute force protection afforded to other Member accounts. Failed login counts were not logged for default admins resulting in unlimited attempts on the default admin username and password.
Пакеты
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 3.1.18, < 3.1.19
3.1.19
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 3.2.3, < 3.2.4
3.2.4
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
>= 3.3.1, < 3.3.2
3.3.2
9.1 Critical
CVSS3
Дефекты
CWE-307
9.1 Critical
CVSS3
Дефекты
CWE-307