3.1.0
6 years ago
15 days ago
Known vulnerabilities in the django-mfa2 package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
django-mfa2 is an Allows user to add 2FA to their accounts Affected versions of this package are vulnerable to Replay Attack by allowing an attacker to register another device for a user, when the device registration challenge not being invalidated after usage. How to fix Replay Attack? Upgrade | [,2.5.2)[2.6.0,2.6.1) |