Опубликовано: 10 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.9
Описание
ajenti.plugin.core has race conditions in 2FA
Impact
If the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication.
Patches
This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.
Пакеты
Наименование
ajenti.plugin.core
pip
Затронутые версииВерсия исправления
<= 0.111
0.112
EPSS
Процентиль: 14%
0.00232
Низкий
6.9 Medium
CVSS4
5.9 Medium
CVSS3
CVE ID
Дефекты
CWE-287
CWE-362
Связанные уязвимости
CVSS3: 5.9
nvd
4 месяца назад
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.
CVSS3: 5.9
debian
4 месяца назад
ajenti.plugin.core defines all necessary core elements to allow Ajenti ...
EPSS
Процентиль: 14%
0.00232
Низкий
6.9 Medium
CVSS4
5.9 Medium
CVSS3
CVE ID
Дефекты
CWE-287
CWE-362