CVE-2020-27508: High severity frappe lms vulnerability
Published Dec 11, 2020
·Updated
In two-factor authentication, the system also sending 2fa secret key in response, which enables an intruder to breach the 2fa security.
Affected Software
1 affected component
Frappe frappe<12.10.0
Remediation
Patch Available
Patch Available
Event History
Dec 11, 2020
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
Description
Frequently Asked Questions
1
What is CVE-2020-27508?
CVE-2020-27508 is a vulnerability in the Frappe software that allows an intruder to breach the two-factor authentication security by receiving the 2fa secret key in the response.
2
What is the severity of CVE-2020-27508?
The severity of CVE-2020-27508 is high, with a severity value of 7.5.
3
How does CVE-2020-27508 affect Frappe?
CVE-2020-27508 affects Frappe versions up to and excluding 12.10.0
4
How can I fix CVE-2020-27508?
To fix CVE-2020-27508, you should update Frappe to a version beyond 12.10.0
5
Where can I find more information about CVE-2020-27508?
You can find more information about CVE-2020-27508 on the Frappe GitHub repository, in pull requests 11262 and 11263.