SB2024061943 - MFA bypass in Firefly III



SB2024061943 - MFA bypass in Firefly III

Published: June 19, 2024

Security Bulletin ID SB2024061943
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass using an alternate path or channel (CVE-ID: CVE-2024-37893)

The vulnerability allows a remote attacker to bypass MFA checks.

The vulnerability exists due to an error within the Firefly III OAuth flow. A remote attacker can bypass MFA checks and gain unauthorized access to the application.

Note, successful exploitation of the vulnerability requires knowledge of the victim's password.


Remediation

Install update from vendor's website.