Authenticator Login Plus (2FA)
It provides two factor verification for the login process.
A person with a valid password reset link could access an account without passing the second security step. They could skip the extra security check entirely. This could allow them to see and change restricted data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker has access to a valid one time login link for a victim.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Authenticator Login Plus (2FA) to 1.0.1.
For developers: what the fix changed
The fix updates src/Form/LoginChallengeForm.php and src/Controller/ResetRequestController.php to properly enforce two factor authentication for users logging in via a one time login link. It ensures these users are correctly redirected to the password reset page after verification.
README.md+11 −8auth_login_plus.services.yml+2 −0 fixsrc/Controller/ResetRequestController.php+6 −0 fixsrc/Controller/RestLoginController.php+17 −0 fixsrc/EventSubscriber/LoginEnforcementSubscriber.php+4 −2 fixsrc/Form/LoginChallengeForm.php+9 −2 fixsrc/Form/UserEnrollForm.php+49 −3 fixsrc/Hook/AuthLoginPlusHooks.php+25 −0src/Service/LoginChallengeManager.php+138 −8