Open Social - Moderately critical - Denial of Service - SA-CONTRIB-2024-038

Джерело:
Security advisories for contributed projects

Дата публікації:
04/09/2024 19:20

Постійна адреса новини:
http://www.vsinovyny.com/11264079

Open Social - Moderately critical - Denial of Service - SA-CONTRIB-2024-038

 

04/09/2024 19:20 // Security advisories for contributed projects

Project: 
Date: 
2024-September-04
Security risk: 
Vulnerability: 
Denial of Service
Affected versions: 
<12.3.8 || >=12.4.0 <12.4.5 || >=13.0.0 <13.0.0-alpha11
Description: 

Open Social is a Drupal distribution for online communities.

The distribution didn't validate the flood control limits on the password reset form correctly resulting in a potential attacker flooding the password reset which could result in a Denial of Service. Fortunately the message does not disclose any information to the attacker.

Solution: 

Install the latest version:

Reported By: 
Fixed By: 
Coordinated By: 

 

» Читати повністю

 

« Наступна новина з архіву
Стало відомо, де поселятимуть львів'ян, чиє житло знищили ранкові російські атаки
  Попередня новина з архіву
Open Social - Moderately critical - Cross Site Scripting, Denial of Service - SA-CONTRIB-2024-037
»

 

 
© 2026 www.vsinovyny.com