AdminBundle\Security\PimcoreUserTwoFactorCondition
introduced in v11 disable the two factor authentication for all non-admin security firewalls.
An authenticated user can access the system without having to provide the 2 factor credentials.
Apply patch https://patch-diff.githubusercontent.com/raw/pimcore/admin-ui-classic-bundle/pull/345.patch
Upgrade to version 1.2.2 or apply the patch manually.
{ "nvd_published_at": "2023-11-28T05:15:08Z", "cwe_ids": [ "CWE-308" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-11-27T23:23:02Z" }