{"id":"GHSA-h6mp-mc7g-mg49","aliases":[],"url":"https://o3.security/vulnerability/GHSA-h6mp-mc7g-mg49","summary":"scheb/two-factor-bundle bypass two-factor authentication with unverified JWT trusted device token","details":"Before version 3.7 the bundle is vulnerable to a [security issue in JWT](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/), which can be exploited by an attacker to generate trusted device cookies on their own, effectively by-passing two-factor authentication.","published":"2024-05-21T18:16:24Z","modified":"2024-12-06T05:39:49.642018Z","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"scheb/two-factor-bundle","fixedVersion":"3.7.0"}],"fix":{"url":"https://github.com/scheb/two-factor-bundle/commit/8890c1e47ae89e0ac6f8a40fd4bb4b91c2081aa7","label":"scheb/two-factor-bundle@8890c1e"},"references":[{"type":"WEB","url":"https://github.com/scheb/two-factor-bundle/issues/143"},{"type":"WEB","url":"https://github.com/scheb/two-factor-bundle/commit/8890c1e47ae89e0ac6f8a40fd4bb4b91c2081aa7"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/scheb/two-factor-bundle/2018-07-08.yaml"},{"type":"PACKAGE","url":"https://github.com/scheb/two-factor-bundle"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:39:49.642018Z"}}