VDB
Sign up
HIGH7.4

GHSA-h6mp-mc7g-mg49

scheb/two-factor-bundle bypass two-factor authentication with unverified JWT trusted device token

Quick fix

GHSA-h6mp-mc7g-mg49 — scheb/two-factor-bundle: upgrade to the fixed version with the command below.

composer require scheb/two-factor-bundle:^3.7.0

Details

Before version 3.7 the bundle is vulnerable to a [security issue in JWT](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/), which can be exploited by an attacker to generate trusted device cookies on their own, effectively by-passing two-factor authentication.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/scheb/two-factor-bundle
Introduced in: 3.0.0Fixed in: 3.7.0
Fixcomposer require scheb/two-factor-bundle:^3.7.0

References