it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001
- Date: Wed, 8 Jan 2025 18:39:43 +0000 (UTC)
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Ax8oVx7e; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; dmarc=pass (policy=none) header.from=drupal.org
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 9D39760A7E
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp2.osuosl.org 2F82A408EA
- List-archive: <http://lists.drupal.org/pipermail/security-news/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2025-001
Project: Email TFA [1]
Date: 2025-January-08
Security risk: *Moderately critical* 14 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Access bypass
Affected versions: <2.0.3
Description:
This module enables you to do Two-Factor Authentication by email, using a
user registered email to send a verification code to the user's email every
time the user tries to log in to your site.
The module did not sufficiently protect against brute force attacks, allowing
an attacker to bypass the second factor.
This vulnerability is mitigated by the fact the attacker must be able to
present the username and first factor (i.e. password).
Solution:
Install the latest version:
* If you use the Email TFA module, upgrade to Email TFA 2.0.3 [3]
Reported By:
* Ursin Cola [4]
Fixed By:
* Ursin Cola [5]
* abdulaziz zaid [6]
Coordinated By:
* Greg Knaddison [7] of the Drupal Security Team
* Juraj Nemec [8] of the Drupal Security Team
[1] https://www.drupal.org/project/email_tfa
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/email_tfa/releases/2.0.3
[4] https://www.drupal.org/user/679260
[5] https://www.drupal.org/user/679260
[6] https://www.drupal.org/user/3585656
[7] https://www.drupal.org/user/36762
[8] https://www.drupal.org/user/272316
_______________________________________________
Security-news mailing list
Security-news AT drupal.org
Unsubscribe at https://lists.drupal.org/mailman/listinfo/security-news
- [IT-SecNots] [Security-news] Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001, security-news, 08.01.2025
Archiv bereitgestellt durch MHonArc 2.6.19+.