PT-2024-25635 · Mfa+2 · Mfa+2

Petr Skoda

·

Published

2024-05-31

·

Updated

2025-05-31

·

CVE-2024-34007

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MFA (affected versions not specified)
Description The issue concerns the logout option within MFA, which did not include the necessary token to prevent the risk of users being inadvertently logged out via CSRF.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

CSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2024-8851
ALT-PU-2024-9067
BIT-MOODLE-2024-34007
CVE-2024-34007
GHSA-8G5H-GJWQ-W5CH

Affected Products

Alt Linux
Mfa
Red Os