PT-2024-40226 · Unknown · Scheb/Two-Factor-Bundle
Published
2024-05-21
·
Updated
2024-05-21
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
scheb/two-factor-bundle versions prior to 3.26.0
scheb/two-factor-bundle versions prior to 4.11.0
Description:
A security issue allowed attackers to bypass two-factor authentication (2FA) using the remember me cookie. When the remember me checkbox was used during login, a "REMEMBERME" cookie was created. Upon redirection to the 2FA page, attackers could manipulate the SESSIONID key, granting access to the homepage "/" and gaining authentication without completing 2FA.
Recommendations:
For versions prior to 3.26.0, update to version 3.26.0 or later to resolve the issue.
For versions prior to 4.11.0, update to version 4.11.0 or later to resolve the issue.
As a temporary workaround, consider disabling the remember me feature until a patch is available.
Restrict access to the SESSIONID key to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scheb/Two-Factor-Bundle