Impact
- it requires to know 2 valid login+password (in my case, both have 2FA configured
- I connect to https://eyedp.example.com/users/sign_in and use one of my accounts; it then asks me for 2FA, which I don't enter
- I then go to my URL bar and hit Enter again (in order to load this same page again, but not using the "reload" button)
- the login+password screen appears again; I enter my other credentials. EyeDP accepts my login without asking me for 2FA.
Patches
This has been resolved on both the main branch as well as the v1.0.9 tag
Workarounds
None, all users should upgrade
More info
Identified by: KheOps
Impact
Patches
This has been resolved on both the main branch as well as the v1.0.9 tag
Workarounds
None, all users should upgrade
More info
Identified by: KheOps