Ory Kratos's setting required_aal highest_available does not properly respect code + mfa credentials in github.com/ory/kratos
highest_available
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-3160" }