2FA is bypassed right after password reset #7874
Unanswered
DocSneider
asked this question in
Error / Bug Report
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Summary
After Password Reset, the 2FA is not called and the user gets logged in directly.
Details
When using the "built-in authentication" and receiving a password reset link, the 2FA (TOTP) will be bypassed after changing the password, even if 2FA is forced for all users.
If logging out and in again, the 2FA check is called again.
PoC
Impact
If an attacker gets access to a users mail account, he can reset the password and login without 2nd factor.
This completely circumvents the intended protection provided by 2FA.
(Already reported this in https://github.com/requarks/wiki/security/advisories/GHSA-xj3p-gj3h-jf58 on 08.01.2025)
Beta Was this translation helpful? Give feedback.
All reactions