PT-2024-40226 · Unknown · Scheb/Two-Factor-Bundle

Published

2024-05-21

·

Updated

2024-05-21

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: scheb/two-factor-bundle versions prior to 3.26.0 scheb/two-factor-bundle versions prior to 4.11.0
Description: A security issue allowed attackers to bypass two-factor authentication (2FA) using the remember me cookie. When the remember me checkbox was used during login, a "REMEMBERME" cookie was created. Upon redirection to the 2FA page, attackers could manipulate the SESSIONID key, granting access to the homepage "/" and gaining authentication without completing 2FA.
Recommendations: For versions prior to 3.26.0, update to version 3.26.0 or later to resolve the issue. For versions prior to 4.11.0, update to version 4.11.0 or later to resolve the issue. As a temporary workaround, consider disabling the remember me feature until a patch is available. Restrict access to the SESSIONID key to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-9PHW-7H96-Q3RV

Affected Products

Scheb/Two-Factor-Bundle