spryker/agent-security-merchant-portal-gui is vulnerable to Auth Bypass
60
Medium Risk
Affected versions of this package are vulnerable to Multi-Factor Authentication Bypass via Improper Code Invalidation due to an adjusted user authentication flow that invalidates active MFA codes before login and verifies login status during validation. This flaw allows an attacker to invalidate a user's MFA codes prematurely, potentially bypassing MFA requirements or causing login failures. An attacker could exploit this by initiating login attempts that trigger MFA invalidation without completing authentication, leading to account lockout or unauthorized access if the system fails to properly validate the user's login state during MFA verification.
You are affected if you are using a version that falls within the vulnerable range.
spryker/agent-security-merchant-portal-gui is vulnerable to Auth Bypass in versions 1.3.0 - 1.4.0.
Upgrade the spryker/agent-security-merchant-portal-gui library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant