CVE-2024-13274: Drupal Open Social allows Functionality Misuse
(updated )
The distribution didn’t validate the flood control limits on the password reset form correctly resulting in a potential attacker flooding the password reset which could result in a Denial of Service. Fortunately the message does not disclose any information to the attacker.
References
Detect and mitigate CVE-2024-13274 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →