DRUPAL-CONTRIB-2023-030
Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2023-030
DRUPAL-CONTRIB-2023-030
Published: 12 Jul 2023Last Modified: 10 Sept 2026
Summary:
Details: This module enables you to allow and/or require users to use a second authentication method in addition to password authentication. The module doesn't sufficiently ensure all core login routes, including the password reset page, require a second factor credential. This vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.
References: https://www.drupal.org/sa-contrib-2023-030
Affected packages
Package
Name: drupal/tfa
Purl: pkg:composer/drupal/tfa?repository_url=https:%2F%2Fpackages.drupal.org%2F8
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 1.0.0
Fixed -1.1.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
