Security Advisory: Mail Login Module Vulnerability SA-CONTRIB-2023-048

security for website
Freepik

The Mail Login module for Drupal has recently been flagged for a moderately critical security issue, designated as SA-CONTRIB-2023-048. The vulnerability, assessed with a risk level of 13/25, pertains to an access bypass that potentially exposes users to brute-force attacks. Specifically, the module lacks the flood control mechanism present in Drupal core, making it susceptible to such attacks.

Users are advised to update to the latest version of the Mail Login module to mitigate this security risk. For those using Drupal versions 8, 9, or 10, upgrading to Mail Login 8.x-2.9 is recommended. It's crucial to note that a previous security advisory, SA-CONTRIB-2023-45, attempted to address this issue but did not provide an effective solution. Therefore, the current security advisory and the updated module version supersede the previous attempt.

Melisa Cordero and Emil Johnsson reported and resolved the vulnerability through a team effort. Key members of the Drupal Security Team oversaw the coordination of this security matter. This security advisory underscores the ongoing efforts to maintain the integrity and security of Drupal-based websites. For more information, visit the website.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please let us know in the comments below and we will try to address the issue as best we can.

Advertisement Here

Upcoming Events

Latest Opportunities

Advertisement Here

Call for Support