CVE-2024-41800: Craft CMS Allows TOTP Token To Stay Valid After Use
Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period.
References
- github.com/advisories/GHSA-wmx7-pw49-88jx
- github.com/craftcms/cms
- github.com/craftcms/cms/commit/7c790fa5ad5a8cb8016cb6793ec3554c4c079e38
- github.com/craftcms/cms/security/advisories/GHSA-wmx7-pw49-88jx
- github.com/sbaresearch/advisories/tree/public/2024/SBA-ADV-20240617-01_CraftCMS_TOTP_Valid_After_Use
- nvd.nist.gov/vuln/detail/CVE-2024-41800
Detect and mitigate CVE-2024-41800 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →