Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-3p4x-grpm-xw58: Password hash exposed in CraftCMS two factor authentication plugin

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

ghsa
#git#auth

Password hash exposed in CraftCMS two factor authentication plugin

Low severity GitHub Reviewed Published Jun 6, 2024 to the GitHub Advisory Database • Updated Jun 6, 2024

ghsa: Latest News

GHSA-x7m9-mv49-fv73: Vaultwarden vulnerable to user impersonation