django-mfa3@0.2.3 vulnerabilities

multi factor authentication for django

  • latest version

    0.15.1

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the django-mfa3 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Authentication Bypass

    django-mfa3 is a multi factor authentication for django

    Affected versions of this package are vulnerable to Authentication Bypass by not modifying the admin login view in order for the multi-factor authentication to work.

    How to fix Authentication Bypass?

    Upgrade django-mfa3 to version 0.5.0 or higher.

    [,0.5.0)