Authentication bypass using an alternate path or channel in Firefly III - CVE-2024-37893
Published: June 19, 2024
Vulnerability identifier: #VU92253
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37893
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass MFA checks.
The vulnerability exists due to an error within the Firefly III OAuth flow. A remote attacker can bypass MFA checks and gain unauthorized access to the application.
Note, successful exploitation of the vulnerability requires knowledge of the victim's password.
Affected software
Firefly III
How to mitigate CVE-2024-37893
Install updates from vendor's website.
Firefly III - update to 6.1.18