First published: Tue Oct 01 2024(Updated: )
Benoit Côté-Jodoin and Michael Nipper discovered that Devise-Two-Factor incorrectly handled one-time password validation. An attacker could possibly use this issue to intercept and re-use a one-time password. (CVE-2021-43177) Garrett Rappaport discovered that Devise-Two-Factor incorrectly handled generating multi-factor authentication codes. An attacker could possibly use this issue to generate valid multi-factor authentication codes. (CVE-2024-8796)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/ruby-devise-two-factor | <4.0.0-2ubuntu0.1~esm1 | 4.0.0-2ubuntu0.1~esm1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/ruby-devise-two-factor | <3.1.0-2ubuntu0.1~esm1 | 3.1.0-2ubuntu0.1~esm1 |
Ubuntu Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.