-
-
Notifications
You must be signed in to change notification settings - Fork 302
Closed
Description
I'm a pentester from Radically Open Security.
We recently reported a 2FA bypass vulnerability in the devise-two-factor library, see the GHSA-chcr-x7hc-8fp8 advisory and my writeup.
Since Bullet Train uses the devise-two-factor library for 2FA authentication, we recommend looking into this as a potential security problem you could be affected by. Please note that we have not further analyzed your project code.
Relevant gem definition:
Line 140 in cd59fff
| gem "devise-two-factor" |
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels