Boletines de Vulnerabilidades

MSA-22-0014: Failed login attempts counted incorrectly


Información sobre el sistema

   
Software afectado PHP

Descripción

by Michael Hawkins. An issue in the logic used to count failed login attempts could result in the account lockout threshold being bypassed.Severity/Risk:SeriousVersions affected:4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versionsVersions fixed:4.0.1, 3.11.7, 3.10.11 and 3.9.14Reported by:Shamim RezaieCVE identifier:CVE-2022-30600Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-73736Tracker issue:MDL-73736

More info:

https://moodle.org/mod/forum/discuss.php?d=434582&parent=1748726

Identificadores estándar

Propiedad Valor
CVE CVE-2022-30600.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2022-05-18
Ministerio de Defensa
CNI
CCN
CCN-CERT