Description
The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2943 | The Admin Classic Bundle provides a Backend UI for Pimcore. `AdminBundle\Security\PimcoreUserTwoFactorCondition` introduced in v11 disable the two factor authentication for all non-admin security firewalls. An authenticated user can access the system without having to provide the two factor credentials. This issue has been patched in version 1.2.2. |
Github GHSA |
GHSA-9wwg-r3c7-4vfg | Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T21:46:29.190Z
Reserved: 2023-11-21T18:57:30.427Z
Link: CVE-2023-49075
No data.
Status : Modified
Published: 2023-11-28T05:15:08.160
Modified: 2024-11-21T08:32:46.087
Link: CVE-2023-49075
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA