Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.1
Описание
LinOTP replay vulnerability with auto resynchronization enabled for TOTP token
LinOTP is prone to a replay attack with activated automatic resynchronization. This vulnerability may allow an attacker to successfully log in with OTP values recorded at a previous point in time.
This attack is only possible if automatic resynchronization is enabled for the TOTP token type. The automatic resynchronization is deactivated by default. All other tokens are unaffected.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-12887
- https://github.com/LinOTP/LinOTP/commit/6d28d93af59d2ce0d844a6a3282148064efc6ad8
- https://github.com/pypa/advisory-database/tree/main/vulns/linotp/PYSEC-2019-103.yaml
- https://linotp.org/linotp-hotfix-autoresync.html
- https://www.linotp.org/CVE-2019-12887.txt
Пакеты
Наименование
LinOTP
pip
Затронутые версииВерсия исправления
< 2.11.1
2.11.1
Связанные уязвимости
CVSS3: 8.1
nvd
больше 6 лет назад
KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2).