HIGH7.4
GHSA-h6mp-mc7g-mg49
scheb/two-factor-bundle bypass two-factor authentication with unverified JWT trusted device token
Quick fix
GHSA-h6mp-mc7g-mg49 — scheb/two-factor-bundle: upgrade to the fixed version with the command below.
composer require scheb/two-factor-bundle:^3.7.0Details
Before version 3.7 the bundle is vulnerable to a [security issue in JWT](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/), which can be exploited by an attacker to generate trusted device cookies on their own, effectively by-passing two-factor authentication.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/scheb/two-factor-bundle
Introduced in:
3.0.0Fixed in: 3.7.0Fix
composer require scheb/two-factor-bundle:^3.7.0References
- https://github.com/scheb/two-factor-bundle/issues/143[WEB]
- https://github.com/scheb/two-factor-bundle/commit/8890c1e47ae89e0ac6f8a40fd4bb4b91c2081aa7[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/scheb/two-factor-bundle/2018-07-08.yaml[WEB]
- https://github.com/scheb/two-factor-bundle[PACKAGE]