GHSA-rqg8-xjp2-pg9w
Dashboard / Vulnerabilities / GHSA-rqg8-xjp2-pg9w
GHSA-rqg8-xjp2-pg9w
Summary: LinOTP replay vulnerability with auto resynchronization enabled for TOTP token
Details: LinOTP is prone to a replay attack with activated automatic resynchronization. This vulnerability may allow an attacker to successfully log in with OTP values recorded at a previous point in time. This attack is only possible if automatic resynchronization is enabled for the TOTP token type. The automatic resynchronization is deactivated by default. All other tokens are unaffected.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-12887, https://github.com/LinOTP/LinOTP/commit/6d28d93af59d2ce0d844a6a3282148064efc6ad8, https://github.com/LinOTP/LinOTP, https://github.com/pypa/advisory-database/tree/main/vulns/linotp/PYSEC-2019-103.yaml, https://linotp.org/linotp-hotfix-autoresync.html, https://www.linotp.org/CVE-2019-12887.txt
Affected packages
Package
Name: linotp
Purl: pkg:pypi/linotp
Affected ranges
Type: ECOSYSTEM
Events:
