Vulnerability Bulletins

MSA-22-0014: Failed login attempts counted incorrectly


System information

   
Affected software PHP

Description

by Michael Hawkins. An issue in the logic used to count failed login attempts could result in the account lockout threshold being bypassed.Severity/Risk:SeriousVersions affected:4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versionsVersions fixed:4.0.1, 3.11.7, 3.10.11 and 3.9.14Reported by:Shamim RezaieCVE identifier:CVE-2022-30600Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-73736Tracker issue:MDL-73736

More info:

https://moodle.org/mod/forum/discuss.php?d=434582&parent=1748726

Standar resources

Property Value
CVE CVE-2022-30600.

Version history

Version Comments Date
1.0 Advisory issued 2022-05-18
Ministerio de Defensa
CNI
CCN
CCN-CERT