CVE-2025-7030
EPSS 0.36%
Description
This module enables you to allow and/or require a second authentication method in addition to password authentication. The module does not sufficiently ensure that users with enhanced privileges are prevented from viewing recovery codes of other users. This vulnerability is mitigated by the fact that an attacker must have a role with the *Administer TFA for other users* permission.
How to fix CVE-2025-7030
To remediate CVE-2025-7030, upgrade the affected package to a fixed version below.
- Packagist/drupal/tfa—upgrade to 1.11.0 or later
Is CVE-2025-7030 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.11.0