Описание
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.
EPSS
Процентиль: 19%
0.00269
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-288
Связанные уязвимости
CVSS3: 6.5
github
5 дней назад
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing second-factor verification by exploiting premature session caching.
EPSS
Процентиль: 19%
0.00269
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-288