drupal/tfa is vulnerable to Improper Privilege Management
60
Medium Risk
Affected versions of this package are vulnerable due to incorrectly configured access control levels. The module does not adequately prevent privileged users from viewing the recovery codes of other users. This issue is partially mitigated by the requirement that an attacker must possess a role with the "Administer TFA for other users" permission.
You are affected if you are using a version that falls within the vulnerable range.
drupal/tfa is vulnerable to Improper Privilege Management in versions 0.0.0 - 1.10.0.
Upgrade the drupal/tfa library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant