CVE Vulnerabilities

CVE-2013-0258

Improper Authentication

Published: Mar 27, 2013 | Modified: Apr 05, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ga_login Google_authenticator_login_project 7.x-1.0 (including) 7.x-1.0 (including)
Ga_login Google_authenticator_login_project 7.x-1.0-beta1 (including) 7.x-1.0-beta1 (including)
Ga_login Google_authenticator_login_project 7.x-1.0-dev (including) 7.x-1.0-dev (including)
Ga_login Google_authenticator_login_project 7.x-1.1 (including) 7.x-1.1 (including)
Ga_login Google_authenticator_login_project 7.x-1.2 (including) 7.x-1.2 (including)

Potential Mitigations

References