CVE-2013-0258: Medium severity Google Authenticator Login Project Ga Login vulnerability
The Google Authenticator login (galogin) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0258?
CVE-2013-0258 has a medium severity rating as it allows remote attackers to bypass authentication.
How do I fix CVE-2013-0258?
To fix CVE-2013-0258, update the Google Authenticator login module to version 7.x-1.3 or later.
Who is affected by CVE-2013-0258?
CVE-2013-0258 affects users of the Google Authenticator login module versions prior to 7.x-1.3 on Drupal.
What impact does CVE-2013-0258 have?
CVE-2013-0258 allows attackers to log in to accounts without a Google Authenticator token, potentially compromising account security.
Is multi-factor authentication effective against CVE-2013-0258?
While multi-factor authentication is a strong security measure, CVE-2013-0258 allows unauthorized access even when it is enabled.