—
DRUPAL-CONTRIB-2025-023
Details
This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.
The module does not sufficiently ensure that known login routes are not overridden by third-party modules which can allow an access bypass to occur.
This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/tfa
Introduced in:
0Fixed in: 1.10.0Upgrade drupal/tfa to 1.10.0 or newer (ecosystem packagist:https://packages.drupal.org/8).