CVE-2025-8995
描述
This module enables users to setup two-factor authentication (2FA) using authenticator apps for enhanced login security. The module alters the standard Drupal login form to use AJAX callbacks for handling authentication flow. The module doesn't sufficiently validate authentication under specific conditions, allowing an attacker to log in as any account where they know the username. This vulnerability is mitigated by the fact that an attacker must make a series of requests to trigger the necessary conditions that allow authentication byass. The series of requests could alert a site owner that they are being attacked; however, the number of requests necessary to trigger the conditions is usually quite small (the number depends on site configuration, by default it is 5).
如何修補 CVE-2025-8995
要修補 CVE-2025-8995,請將受影響套件升級到下列已修補版本。
- —升級至 2.1.5 或更新版本
CVE-2025-8995 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.1.5