{"id":"CVE-2022-42731","aliases":["GHSA-vw39-2wj9-4q86","PYSEC-2022-303"],"url":"https://o3.security/vulnerability/CVE-2022-42731","summary":"django-mfa2 vulnerable to MFA Replay attack","details":"mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge is not invalidated after usage.","published":"2022-10-11T00:00:00Z","modified":"2026-08-12T03:51:31.375502123Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"django-mfa2","fixedVersion":"2.5.1"},{"ecosystem":"PyPI","name":"django-mfa2","fixedVersion":"2.6.1"}],"fix":{"url":"https://github.com/mkalioby/django-mfa2/commit/54db5a513bcafa97a36e9f6dfa31d3c61fa8217b","label":"mkalioby/django-mfa2@54db5a5"},"references":[{"type":"WEB","url":"https://github.com/mkalioby/django-mfa2/blob/0936ea253354dd95cb127f09d0efa31324caef27/mfa/FIDO2.py#L58"},{"type":"WEB","url":"https://github.com/mkalioby/django-mfa2/releases/tag/v2.5.1-release"},{"type":"WEB","url":"https://github.com/mkalioby/django-mfa2/releases/tag/v2.6.1-release"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/42xxx/CVE-2022-42731.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42731"},{"type":"WEB","url":"https://github.com/mkalioby/django-mfa2/commit/54db5a513bcafa97a36e9f6dfa31d3c61fa8217b"},{"type":"WEB","url":"https://github.com/mkalioby/django-mfa2/commit/5fbb505e98ecdd409330a5c336ad5ec49631b0db"},{"type":"PACKAGE","url":"https://github.com/mkalioby/django-mfa2"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/django-mfa2/PYSEC-2022-303.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.375502123Z"}}