Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

Two-Factor Authentication Bypass in scheb/two-factor-bundle

published 2 years ago
Summary

The scheb/two-factor-bundle is vulnerable to a security issue that allows attackers to bypass two-factor authentication. If exploited, this could let attackers access your system without needing a second form of verification. If you're using version 3.7 or earlier, you should update to the latest version as soon as possible.

What to do
  • Update scheb two-factor-bundle to version 3.7.0.
Affected software
Ecosystem VendorProductAffected versions
composer scheb two-factor-bundle >= 3.0.0, < 3.7.0
Fix: upgrade to 3.7.0
Original advisory text
scheb/two-factor-bundle bypass two-factor authentication with unverified JWT trusted device token
Before version 3.7 the bundle is vulnerable to a [security issue in JWT](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/), which can be exploited by an attacker to generate trusted device cookies on their own, effectively by-passing two-factor authentication.
Severity
7.4 High
CVSS 3.1: 7.4 (GHSA)
Type
CWE-287Improper Authentication
Timeline
Published21 May 2024
Updated6 Mar 2026
First seen6 Mar 2026
Sources
Monitor software like this
Free during beta