CVE-2025-48011
EPSS 0.27%
描述
This module enables you to allow users to include a second authentication method in addition to password authentication. The module doesn't sufficiently prevent TFA from being bypassed when using the REST login routes. A new requirements check has been added to the status report so other authentication providers can be assessed to check if they also allow for this bypass. This vulnerability is mitigated by the fact that an attacker must obtain a valid username/password.
如何修補 CVE-2025-48011
要修補 CVE-2025-48011,請將受影響套件升級到下列已修補版本。
- Packagist/drupal/one_time_password—升級至 1.3.0 或更新版本
CVE-2025-48011 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.3.0