DRUPAL-CONTRIB-2025-098

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/alogin/DRUPAL-CONTRIB-2025-098.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2025-098
Aliases
  • CVE-2025-8093
Published
2025-08-27T17:19:14Z
Modified
2025-12-10T23:41:25.519894Z
Summary
[none]
Details

This module allows users to setup two-factor authentication (2FA) using authenticator apps for enhanced login security.

The module did not protect all possible login paths provided by core modules.

CVSS risk score (experimental) 6.3 / Medium

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/alogin

Package

Name
drupal/alogin
Purl
pkg:composer/drupal/alogin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.8
Database specific
{
    "constraint": "<2.1.8"
}

Database specific

affected_versions
"<2.1.8"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/alogin/DRUPAL-CONTRIB-2025-098.json"