VDB
Sign up
HIGH7.4

GHSA-9phw-7h96-q3rv

scheb/two-factor-bundle bypass two-factor authentication with remember-me option

Quick fix

GHSA-9phw-7h96-q3rv — scheb/two-factor-bundle: upgrade to the fixed version with the command below.

composer require scheb/two-factor-bundle:^4.11.0

Details

In versions prior to 3.26.0 and prior to 4.11.0 of the "scheb/two-factor-bundle" project, a security vulnerability allowed attackers to bypass two-factor authentication (2FA) using the remember_me cookie. When the remember_me checkbox was used during login, a "REMEMBERME" cookie was created. Upon redirection to the 2FA page, attackers could manipulate the SESSIONID key, granting access to the homepage "/" and gaining authentication without completing 2FA.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/scheb/two-factor-bundle
Introduced in: 4.0.0Fixed in: 4.11.0
Fixcomposer require scheb/two-factor-bundle:^4.11.0
Packagist/scheb/two-factor-bundle
Introduced in: 0Fixed in: 3.26.0
Fixcomposer require scheb/two-factor-bundle:^3.26.0

References