Login Disable
The module does not stop attackers from repeatedly guessing the secret key. An ordinary account on the site could guess the key to bypass the login block. They could then read some restricted data and change or add some data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if an attacker has a valid username and password.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Login Disable to 2.1.4.
For developers: what the fix changed
In login_disable.module, the _login_disable_form_user_login_alter function was updated to integrate flood control, registering failed attempts and blocking access when the limit is reached.
Also in this release Added a GitLab CI test variable and updated the README file.
.gitlab-ci.yml+2 −0README.txt+6 −0login_disable.module+30 −8 fix