Vulnerabilities > Heroiclabs

DATE CVE VULNERABILITY TITLE RISK
2022-07-05 CVE-2022-2321 Improper Restriction of Excessive Authentication Attempts vulnerability in Heroiclabs Nakama
Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0.
network
low complexity
heroiclabs CWE-307
critical
9.8
2022-07-05 CVE-2022-2306 Insufficient Session Expiration vulnerability in Heroiclabs Nakama
Old session tokens can be used to authenticate to the application and send authenticated requests.
network
low complexity
heroiclabs CWE-613
7.5