GHSA-6w4v-qr4m-97gg
Dashboard / Vulnerabilities / GHSA-6w4v-qr4m-97gg
Summary: Multi-Factor Authentication issue in Laravel Fortify
Details: Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-25838, https://github.com/laravel/fortify/issues/201, https://github.com/laravel/fortify/issues/201#issuecomment-1009282153, https://github.com/laravel/fortify/pull/357, https://github.com/laravel/fortify/pull/358, https://github.com/FriendsOfPHP/security-advisories/blob/master/laravel/fortify/CVE-2022-25838.yaml, https://github.com/advisories/GHSA-6w4v-qr4m-97gg, https://github.com/laravel/fortify
Affected packages
Package
Name: laravel/fortify
Purl: pkg:composer/laravel/fortify
Affected ranges
Type: ECOSYSTEM
Events:
