First published: Fri Dec 11 2020(Updated: )
In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Frappe LMS | <12.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27508 is a vulnerability in the Frappe software that allows an intruder to breach the two-factor authentication security by receiving the 2fa secret key in the response.
The severity of CVE-2020-27508 is high, with a severity value of 7.5.
CVE-2020-27508 affects Frappe versions up to and excluding 12.10.0
To fix CVE-2020-27508, you should update Frappe to a version beyond 12.10.0
You can find more information about CVE-2020-27508 on the Frappe GitHub repository, in pull requests 11262 and 11263.