Headline
GHSA-8wj3-cpmr-8whp: Cockpit Content Platform vulnerable to 2FA bypass
Cockpit Content Platform through version 2.2.1 is vulnerable to a two-factor authentication (2FA) bypass. The 2FA secret is disclosed in a JWT token after user logs into their account, allowing an attacker to bypass the 2FA code. A patch is available on the develop
branch and is expected to be part of version 2.2.2.
Cockpit Content Platform vulnerable to 2FA bypass
High severity GitHub Reviewed Published Aug 16, 2022 • Updated Aug 18, 2022
Related news
CVE-2022-2818: 2FA Bypass in Cockpit Content Platform ≤ v2.2.1 in cockpit
Authentication Bypass by Primary Weakness in GitHub repository cockpit-hq/cockpit prior to 2.2.2.