Drupal Security Update – 13 July 2023

Drupal has released a security update to fix a vulnerability in the Drupal Two-factor Authentication module versions before tfa 8.x-1.1.

The addressed vulnerability could allow the remote attacker to bypass access restrictions to reset the password by sending a specially crafted request to the affected products.

Two-factor Authentication Module for Drupal Security Bypass Vulnerability (SACONTRIB- 2023-030):

  • CVSS: 8.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities

SA-CONTRIB-2023-030

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Drupal Security Advisory

References