—
DRUPAL-CONTRIB-2023-048
Details
This module enables users to log in by email address with minimal configurations.
Drupal core contains protection against brute force attacks via a flood control mechanism. This module's functionality did not replicate the flood control, enabling brute force attacks.
A previous security advisory, [SA-CONTRIB-2023-45](https://www.drupal.org/sa-contrib-2023-045), was released for this issue, but that release did not successfully address the vulnerability. This security advisory and updated module version supersede the previous one.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/mail_login
Introduced in:
0Fixed in: 2.9.0Upgrade drupal/mail_login to 2.9.0 or newer (ecosystem packagist:https://packages.drupal.org/8).