The module enables you to add second-factor authentication in addition to the default Drupal login.
The module doesn't sufficiently protect certain sensitive routes, allowing an attacker to view or modify various TFA-related settings.
{ "constraint": "<4.7.0" }
{ "constraint": ">=5.0.1 <5.2.0" }
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/miniorange_2fa/DRUPAL-CONTRIB-2025-055.json"
"<4.7.0 || >=5.0.1 <5.2.0"
true