Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m96w-952f-wcxp

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
около 12 лет назад

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-287