MEDIUM4.8
GHSA-96qm-hwhp-2rm8
Improper Authentication in CraftCMS two factor authentication plugin
Quick fix
GHSA-96qm-hwhp-2rm8 — born05/craft-twofactorauthentication: upgrade to the fixed version with the command below.
composer require born05/craft-twofactorauthentication:^3.3.4Details
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/born05/craft-twofactorauthentication
Introduced in:
0Fixed in: 3.3.4Fix
composer require born05/craft-twofactorauthentication:^3.3.4References
- https://nvd.nist.gov/vuln/detail/CVE-2024-5658[ADVISORY]
- https://github.com/born05/craft-twofactorauthentication/commit/89d2339463c0f3ee690e707d4bc8501360885289[WEB]
- https://github.com/born05/craft-twofactorauthentication[PACKAGE]
- https://github.com/born05/craft-twofactorauthentication/releases/tag/3.3.4[WEB]
- https://github.com/sbaresearch/advisories/tree/public/2024/SBA-ADV-20240202-02_CraftCMS_Plugin_Two-Factor_Authentication_TOTP_Valid_After_Use[WEB]
- https://plugins.craftcms.com/two-factor-authentication?craft4[WEB]
- http://www.openwall.com/lists/oss-security/2024/06/06/2[WEB]