drupal/captcha is vulnerable to Access bypass
60
Medium Risk
The module does not properly invalidate previously used security tokens in certain scenarios, allowing the CAPTCHA mechanism to be bypassed on subsequent submissions. Exploitation requires an attacker to first solve at least one CAPTCHA manually in order to obtain valid tokens.
You are affected if you are using a version that falls within the vulnerable range.
drupal/captcha is vulnerable to Access bypass in versions 0.0.1 - 1.16.0 and 2.0.0 - 2.0.9.
Upgrade the drupal/captcha library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant