DRUPAL-CONTRIB-2024-038
Withdrawn 2026-03-18. This finding no longer applies and is kept for reference. It is not used when checking packages.
Details
Open Social is a Drupal distribution for online communities.
The distribution didn't validate the flood control limits on the password reset form correctly resulting in a potential attacker flooding the password reset which could result in a Denial of Service. Fortunately the message does not disclose any information to the attacker.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/social
Introduced in:
0Fixed in: 12.3.8Upgrade drupal/social to 12.3.8 or newer (ecosystem packagist:https://packages.drupal.org/8).