drupal/email_tfa is vulnerable to Access bypass
50
Medium Risk
The Email TFA module adds email-based two-factor authentication (2FA) to Drupal logins. In some cases, the module fails to fully enforce 2FA across all login methods, allowing users to bypass the additional authentication step. This vulnerability is mitigated by the fact that an attacker must already possess valid login credentials (username and password) to exploit it.
You are affected if you are using a version that falls within the vulnerable range.
drupal/email_tfa is vulnerable to Access bypass in versions 1.0.0 - 2.0.5.
Upgrade the drupal/email_tfa library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant