born05/craft-twofactorauthentication
Craft 4 plugin for two-factor or two-step login using Time Based OTP.
Activity
- Latest release
- 2y ago
- Total releases
- 68
- Cadence
- ~16 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- May 05, 2017
| Version | Released | |
|---|---|---|
3.4.0
minor
| ||
3.3.7
patch
| ||
3.3.6
patch
| ||
3.3.5
patch
| ||
3.3.4
patch
| ||
3.3.3
patch
2 CVEs
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev
CVE-2024-5657
GHSA-3p4x-grpm-xw58
Jun 06, 2024
Password hash exposed in CraftCMS two factor authentication plugin
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP. Affected versions
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.3.2
patch
2 CVEs
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev
CVE-2024-5657
GHSA-3p4x-grpm-xw58
Jun 06, 2024
Password hash exposed in CraftCMS two factor authentication plugin
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP. Affected versions
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.3.1
patch
2 CVEs
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev
CVE-2024-5657
GHSA-3p4x-grpm-xw58
Jun 06, 2024
Password hash exposed in CraftCMS two factor authentication plugin
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP. Affected versions
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.2.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.11.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.11.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.10.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.0.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
3.0.0-beta.1
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.10.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.9.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.8.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.8.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.7.4
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.7.3.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.7.3
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.7.2
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.7.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.7.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.7.0-beta.1
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.6.3
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.6.2
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.6.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.6.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.1.0-beta.2
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.1.0-beta.1
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.0-beta.14
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.0-beta.13
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.0-beta.12
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.0-beta.11
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.0-beta.10
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev | ||
2.0.0-beta.9
pre
1 CVE
CVE-2024-5658
GHSA-96qm-hwhp-2rm8
Jun 06, 2024
Improper Authentication in CraftCMS two factor authentication plugin
4.8
/ 10
Medium
Network
High
Low
Required
Unchanged
None
High
None
The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
1.0.0
1.0.1
1.1.0
2.0.0
2.0.0-beta
2.0.0-beta.1
+ 51 more Show less
2.0.0-beta.10
2.0.0-beta.11
2.0.0-beta.12
2.0.0-beta.13
2.0.0-beta.14
2.0.0-beta.2
2.0.0-beta.3
2.0.0-beta.4
2.0.0-beta.5
2.0.0-beta.6
2.0.0-beta.7
2.0.0-beta.8
2.0.0-beta.9
2.0.1
2.1.0
2.1.0-beta.1
2.1.0-beta.2
2.1.1
2.1.2
2.10.0
2.10.1
2.11.0
2.11.1
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.0-beta.1
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.8.0
2.8.1
2.9.0
3.0.0
3.0.0-beta.1
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.1
3.3.2
3.3.3
Fixed in
3.3.4
References
Updated Jun 10, 2024 · Source: OSV.dev |