CVE-2024-13239: Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2024-003
Published Jan 9, 2025
·Updated
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.
Affected Software
2 affected components
Drupal Two-factor Authentication<1.5.0
Two-factor Authentication Project Two-factor Authentication Drupal<8.x-1.5
Event History
Jan 9, 2025
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13239?
The severity of CVE-2024-13239 is classified as a moderate risk due to potential authentication abuse.
2
How do I fix CVE-2024-13239?
To fix CVE-2024-13239, update the Drupal Two-factor Authentication module to version 1.5.0 or later.
3
What products are affected by CVE-2024-13239?
CVE-2024-13239 affects versions of Drupal Two-factor Authentication prior to 1.5.0.
4
What type of vulnerability is CVE-2024-13239?
CVE-2024-13239 is a weak authentication vulnerability that allows for authentication abuse.
5
When was CVE-2024-13239 reported?
CVE-2024-13239 was reported and cataloged for public awareness in 2024.