VDB
Sign up
—

DRUPAL-CONTRIB-2023-030

Details

This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.

The module doesn't sufficiently ensure all core login routes, including the password reset page, require a second factor credential.

This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/tfa
Introduced in: 1.0.0Fixed in: 1.1.0

Upgrade drupal/tfa to 1.1.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References