—
DRUPAL-CONTRIB-2023-030
Details
This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.
The module doesn't sufficiently ensure all core login routes, including the password reset page, require a second factor credential.
This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/tfa
Introduced in:
1.0.0Fixed in: 1.1.0Upgrade drupal/tfa to 1.1.0 or newer (ecosystem packagist:https://packages.drupal.org/8).