Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vw39-2wj9-4q86: django-mfa2 vulnerable to MFA Replay attack

mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage.

ghsa
#git
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2022-42731

django-mfa2 vulnerable to MFA Replay attack

High severity GitHub Reviewed Published Oct 11, 2022 • Updated Oct 11, 2022

Package

pip django-mfa2 (pip)

Affected versions

< 2.5.1

>= 2.6.0, < 2.6.1

Patched versions

2.5.1

2.6.1

Description

Related news

CVE-2022-42731: Release v2.6.1 - Security Update · mkalioby/django-mfa2

mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage.