Impact
A vulnerability exists in Baserow up to version 2.3.2 where the verify function in the two‑factor authentication endpoint allows an attacker to bypass authentication controls. This flaw results in improper authentication, letting an adversary potentially assume the identity of a legitimate user. The weakness is a classic authentication failure (CWE‑287) and can be used to gain unauthorized access to the application’s data and administrative functions.
Affected Systems
The affected product is Baserow from the vendor Baserow. All deployments running any release prior to 2.3.3 are vulnerable, with the last known safe release being 2.3.3 and later versions mitigating the issue.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity assessment, and no EPSS score is available, so the likelihood of exploitation is unclear. The vulnerability can be exploited remotely, but the description notes that it requires high complexity and is difficult to execute. It is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. Nevertheless, the impact of unauthorized authentication can be substantial if an attacker gains access to privileged accounts.
OpenCVE Enrichment