Mojira Archive
MCL-22967

Minecraft launcher susceptible to brute force attacks

In the Minecraft launcher after clicking settings, accounts, and add Mojang account. The user is prompted to a page that asks for a Mojang account and password. Recently I was trying to login and forgot my password, so I tried many times to login (over a hundred) and it never prevented me for logging in or told me to wait a period of time before logging in. I feel this design of continually allowing a user to login is a security threat as it encourages brute force attacks.

Won't Fix

thatGuy55

2023-01-16, 06:30 AM

2023-01-20, 10:10 AM

2023-01-20, 10:10 AM

0

0

Confirmed

962691

LauncherLogin

2.3.562 (Windows)

-