{"id":"CVE-2025-31694","aliases":["GHSA-hf6c-fgp3-jfch"],"url":"https://o3.security/vulnerability/CVE-2025-31694","summary":null,"details":"This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.\n\nThe module does not sufficiently ensure that known login routes are not overridden by third-party modules which can allow an access bypass to occur.\n\nThis vulnerability is mitigated by the fact that an attacker must obtain a first-factor login credential.","published":"2025-03-05T18:17:14Z","modified":"2026-09-10T03:46:15.753525769Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist:https://packages.drupal.org/8","name":"drupal/tfa","fixedVersion":"1.10.0"}],"fix":null,"references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-023"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:46:15.753525769Z"}}