Authentication bypass using an alternate path or channel in Firefly III - CVE-2024-37893

 

Authentication bypass using an alternate path or channel in Firefly III - CVE-2024-37893

Published: June 19, 2024


Vulnerability identifier: #VU92253
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37893
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass MFA checks.

The vulnerability exists due to an error within the Firefly III OAuth flow. A remote attacker can bypass MFA checks and gain unauthorized access to the application.

Note, successful exploitation of the vulnerability requires knowledge of the victim's password.


Affected software

Firefly III

How to mitigate CVE-2024-37893

Install updates from vendor's website.

Firefly III - update to 6.1.18

External References

Related Security Bulletins