GHSA-63wg-87qv-rw4r
GitHub Security Advisory
Drupal Open Social allows Functionality Misuse
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The distribution didn't validate the flood control limits on the password reset form correctly resulting in a potential attacker flooding the password reset which could result in a Denial of Service. Fortunately the message does not disclose any information to the attacker.
Affected Packages
Packagist
goalgorilla/open_social
Affected versions:
0
(fixed in 12.3.8)
Packagist
goalgorilla/open_social
Affected versions:
12.4.0
(fixed in 12.4.5)
Packagist
goalgorilla/open_social
Affected versions:
13.0.0-alpha1
(fixed in 13.0.0-alpha11)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.