GHSA-52xp-w8hr-xv3c: High severity composer/filament/filament vulnerability
A flaw in the challenge handling for app-based multi-factor authentication allows the second factor to be bypassed. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/filament/filamentto a version that resolves this vulnerability.Fixed in 5.7.0 - Upgrade
Upgrade
composer/filament/filamentto a version that resolves this vulnerability.Fixed in 4.12.0
Event History
Frequently Asked Questions
Which deployments are affected by this issue?
The issue applies to deployments using app-based MFA with recovery codes enabled. Email-based MFA is not affected.
What access does an attacker need to exploit the MFA bypass?
The provided CVSS vector indicates the attacker needs low-level privileges and can exploit the issue remotely without user interaction. The impact includes high confidentiality and integrity impact.