Skip to content

3.9.3

Choose a tag to compare

@rhukster rhukster released this 20 Aug 23:36
· 3 commits to master since this release
609ec40

Bugfix

  • [security] The two-factor step now limits how many wrong codes may be submitted for an account, with its own counter that a fresh password login does not reset, so a six-digit code can no longer be guessed without limit by someone who already has the password (GHSA-9j6w-2q6c-q3q8).
  • [security] Administrators who hold super access only through a group are now recognised as super when guarding account actions, so a lower-privileged user manager can no longer act on them (GHSA-vv8m-jqpm-38x4).