Описание
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
Ссылки
EPSS
Процентиль: 33%
0.00398
Низкий
7.1 High
CVSS3
Дефекты
CWE-294
Связанные уязвимости
CVSS3: 7.1
debian
около 2 месяцев назад
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforce ...
CVSS3: 7.1
github
около 1 месяца назад
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
EPSS
Процентиль: 33%
0.00398
Низкий
7.1 High
CVSS3
Дефекты
CWE-294