{"id":"GHSA-8r94-4h3c-939f","summary":"Improper Restriction of Excessive Authentication Attempts","details":"Nakama Console does not enforce any limit for the number of unsuccessful login attempts.","aliases":["CVE-2022-2321"],"modified":"2023-11-01T04:57:50.665497Z","published":"2022-07-06T00:00:26Z","database_specific":{"github_reviewed_at":"2022-07-06T19:58:27Z","nvd_published_at":"2022-07-05T19:15:00Z","cwe_ids":["CWE-307"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2321"},{"type":"WEB","url":"https://github.com/heroiclabs/nakama/pull/878"},{"type":"WEB","url":"https://github.com/heroiclabs/nakama/commit/e2e02fce80ff33ce45f8a6ebc0b7a99ee0b03824"},{"type":"PACKAGE","url":"https://github.com/heroiclabs/nakama"},{"type":"WEB","url":"https://huntr.dev/bounties/3055b3f5-6b80-4d47-8e00-3500dfb458bc"}],"affected":[{"package":{"name":"github.com/heroiclabs/nakama/v3","ecosystem":"Go","purl":"pkg:golang/github.com/heroiclabs/nakama/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"3.12.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-8r94-4h3c-939f/GHSA-8r94-4h3c-939f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}