CVE-2021-28373
Summary
| CVE | CVE-2021-28373 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-13 21:15:00 UTC |
| Updated | 2021-03-18 16:33:00 UTC |
| Description | The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the git master branch for a short time. However, all end users are explicitly directed to use the git master branch in production. Semantic version numbers such as 21.03 appear to exist, but are automatically generated from the year and month. They are not releases. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tt-rss | Tiny Tiny Rss | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Check_password not called if OTP is enabled - update ASAP if you're using 2FA - Support - Tiny Tiny RSS: Community | MISC | community.tt-rss.org | Issue Tracking, Patch, Vendor Advisory |
| valid OTP code should not be enough to login, oops · 4949e1a590 - tt-rss - Tiny Tiny RSS | MISC | git.tt-rss.org | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.