Cockpit Content Platform through version 2.2.1 is vulnerable to a two-factor authentication (2FA) bypass. The 2FA secret is disclosed in a JWT token after user logs into their account, allowing an attacker to bypass the 2FA code. A patch is available on the develop
branch and is expected to be part of version 2.2.2.
{ "nvd_published_at": "2022-08-15T11:21:00Z", "cwe_ids": [ "CWE-212", "CWE-287", "CWE-305" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-08-18T19:19:58Z" }