SB2024061943 - MFA bypass in Firefly III
Published: June 19, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass using an alternate path or channel (CVE-ID: CVE-2024-37893)
The vulnerability allows a remote attacker to bypass MFA checks.
The vulnerability exists due to an error within the Firefly III OAuth flow. A remote attacker can bypass MFA checks and gain unauthorized access to the application.
Note, successful exploitation of the vulnerability requires knowledge of the victim's password.
Remediation
Install update from vendor's website.