CVE-2025-7030: Two-factor Authentication (TFA) - Less critical - Access bypass - SA-CONTRIB-2025-085
Privilege Defined With Unsafe Actions vulnerability in Drupal Two-factor Authentication (TFA) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.11.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Two-factor Authentication (TFA)to a version that resolves this vulnerability.Fixed in 1.11.0Patch SA-CONTRIB-2025-085
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7030?
CVE-2025-7030 has been classified as a moderate severity vulnerability due to potential exploitation of access control security levels.
How do I fix CVE-2025-7030?
To resolve CVE-2025-7030, update the Drupal Two-factor Authentication (TFA) module to version 1.11.0 or later.
What versions of Drupal Two-factor Authentication are affected by CVE-2025-7030?
CVE-2025-7030 affects all versions of Drupal Two-factor Authentication (TFA) from 0.0.0 up to but not including 1.11.0.
What type of vulnerability is CVE-2025-7030?
CVE-2025-7030 is a Privilege Defined With Unsafe Actions vulnerability related to access control.
Can CVE-2025-7030 allow unauthorized access?
Yes, CVE-2025-7030 can potentially allow unauthorized access due to incorrectly configured access control settings.