Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmmc-8cqj-hfp3

Опубликовано: 03 сент. 2020
Источник: github
Github: Прошло ревью

Описание

Authentication Bypass in otpauth

Versions of otpauth prior to 3.2.8 are vulnerable to Authentication Bypass. The package's totp.validate() function may return positive values for single digit tokens even if they are invalid. This may allow attackers to bypass the OTP authentication by providing single digit tokens.

Recommendation

Upgrade to version 3.2.8 or later.

Пакеты

Наименование

otpauth

npm
Затронутые версииВерсия исправления

< 3.2.8

3.2.8

Дефекты

CWE-287

Дефекты

CWE-287