CVE-2024-8796
CVSS V2 None
CVSS V3 None
Description
Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined by RFC 4226. Using a shared secret shorter than the minimum to generate a multi-factor authentication code could make it easier for an attacker to guess the shared secret and generate valid TOTP codes.
Overview
- CVE ID
- CVE-2024-8796
- Assigner
- SNPS
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-17T17:12:13.468Z
- Last Modified Date
- 2024-09-17T17:40:01.242Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/devise-two-factor/devise-two-factor/security/advisories/GHSA-qjxf-mc72-wjr2 | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-8796 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8796 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 02:22:36 | Added to TrackCVE |