漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
Vulnerability Description
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. After submitting a victim's correct password, an attacker can invoke taskRegenerate2FASecret() during the pending TOTP challenge, overwrite twofa_secret, read the replacement secret from the response, calculate a valid code, and complete authentication without the victim's second factor. This issue is fixed in version 3.8.11.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
Grav 授权问题漏洞
Vulnerability Description
Grav是Grav组织开源的一款基于文件的扁平化内容管理系统。 Grav 2.0.4之前版本和Grav Login Plugin 3.8.11之前版本存在授权问题漏洞,该漏洞源于login.regenerate2FASecret任务仅检查待处理会话用户存在而未要求用户授权,可能导致攻击者在提交受害者正确密码后,在TOTP挑战期间覆盖twofa_secret并完成身份验证。
CVSS Information
N/A
Vulnerability Type
N/A