Two-factor Authentication (TFA) - Critical - Access bypass - SA-CONTRIB-2024-043.
Changes since 7.x-2.3:
- Regenerate the session before displaying the TFA form
- #2656746 by damienmckenna, michaelmol, poker10: Check if Help module is enabled
- #3436886 by poker10: Add GitLab CI D7
- #3436885 by poker10: Creation of dynamic property TfaTestCase::$web_user is deprecated
- #2694723 by nullkernel, junaidpv, Leeteq: Maintenance mode blocks TOTP TFA entry
VCS Label
7.x-2.4
Core compatibility
Release type
Packaged Git sha1
fc54c7e15daf16a962d6ccd436d8e11ccb340d53
Release files
36f2cf73c0ecbbf0345f1565429f1fcb
Release file SHA-1 hash
51e995c6c40bbc66e206b257ce6bdf73f3fbe991
Release file SHA-256 hash
6113a4198c423515251f08426402cd1813f78bf304f66a4e3b72a4b3078406ed
7230a97546a4719137d3b0d532ac5c4b
Release file SHA-1 hash
36b85c7ff58555727205dbb0704b3b3f725a68e9
Release file SHA-256 hash
4070a228ff0d35455fa0ea44c5e8163292911b0b6a577329f3beee87d141e698