Impact
The verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor.
Patches
This issue has been addressed in Weblate 5.13.1 via #16002.
References
Thanks to Nahid Hasan Limon for reporting this issue responsibly.
Impact
The verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor.
Patches
This issue has been addressed in Weblate 5.13.1 via #16002.
References
Thanks to Nahid Hasan Limon for reporting this issue responsibly.