{"id":"CVE-2024-8796","aliases":["GHSA-qjxf-mc72-wjr2"],"url":"https://o3.security/vulnerability/CVE-2024-8796","summary":"Insufficient Default OTP Shared Secret Length","details":"Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes.","published":"2024-09-17T17:12:13.468Z","modified":"2026-08-27T03:56:59.532766420Z","cvss":null,"epss":{"score":0.00641,"percentile":0.49096,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"devise-two-factor","fixedVersion":"6.0.0"},{"ecosystem":"RubyGems","name":"devise-two-factor","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8796.json"},{"type":"ADVISORY","url":"https://github.com/devise-two-factor/devise-two-factor/security/advisories/GHSA-qjxf-mc72-wjr2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8796"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:56:59.532766420Z"}}