CVE-2024-13279: Two-factor Authentication (TFA) - Critical - Access bypass - SA-CONTRIB-2024-043
Published Jan 9, 2025
·Updated
Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.
Affected Software
2 affected components
Drupal Two-factor Authentication<1.8.0
Two-factor Authentication Project Two-factor Authentication Drupal<8.x-1.8
Event History
Jan 9, 2025
CVE Published
via MITRE·07:31 PM
Data Sourced
via MITRE·07:31 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-13279?
CVE-2024-13279 is classified as a major vulnerability due to its session fixation issue.
2
How do I fix CVE-2024-13279?
To fix CVE-2024-13279, upgrade the Drupal Two-factor Authentication module to version 1.8.0 or higher.
3
Which versions of Drupal Two-factor Authentication are affected by CVE-2024-13279?
CVE-2024-13279 affects all versions of Drupal Two-factor Authentication prior to 1.8.0.
4
What impact does CVE-2024-13279 have on user sessions?
CVE-2024-13279 allows attackers to exploit session fixation vulnerabilities, potentially hijacking user sessions.
5
Is CVE-2024-13279 related to any other vulnerabilities?
CVE-2024-13279 is specific to session fixation in Drupal Two-factor Authentication and does not have direct links to other vulnerabilities.