data-govt-nz / ckanext-security

A CKAN extension to hold various security improvements for CKAN
GNU Affero General Public License v3.0
25 stars 31 forks source link

Security bug on OTP #69

Closed maede224 closed 4 months ago

maede224 commented 5 months ago

Hello team, I have recently found a security bug on Ckanext-Security to bypass OTP feature. Would you please give me an email address to send the report?

Nimaj1994 commented 5 months ago

I investigated @maede224 comment and it is true, your otp flow can be disabled from frontend. Please release a fix as it is very urgent for so many projects.

markstuart commented 5 months ago

Hi @maede224, please forward the details to support@madecurious.com and we will investigate and address it.

maede224 commented 5 months ago

Hello @markstuart , Thanks for your attention, I emailed the report.

markstuart commented 4 months ago

Resolved in 4.1.1