Security team only โ€” this specific release is insecure, due to a future version being a security release.

tfa 8.x-1.6

Security Fix: Replay and Denial of Service vulnerability in HOTP plugin

Impacted versions

  • Two-factor Authentication (TFA) 8.x-1.x versions prior to 8.x-1.6
  • Two-factor Authentication (TFA) 2.x versions prior to and including 2.0.0-alpha2

Description

If an incorrect token is entered on the token validation page for a HOTP token the counter would be reset to the equivalent of counter 0.

8.x-1.6
Subscribe to Insecure