A unique key should be generated for a users QR login key and their auto-login key, so the same key cannot be used interchangeably between the two.
The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Moodle | Ubuntu | upstream | * |