CVE-2024-13279
EPSS 0.44%
描述
This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. The module does not sufficiently migrate sessions before prompting for a second factor token. This vulnerability is mitigated by the fact that an attacker must fixate a session on a victim system that is then authenticated with username and password without completing Two Factor authentication. An attacker must gather additional information regarding the entry form after authentication. An attacker must still present a valid token to complete authentication.
如何修補 CVE-2024-13279
要修補 CVE-2024-13279,請將受影響套件升級到下列已修補版本。
- —升級至 1.8.0 或更新版本
CVE-2024-13279 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.8.0