freedomofpress / securedrop

GitHub repository for the SecureDrop whistleblower platform. Do not submit tips here!
https://securedrop.org/
Other
3.62k stars 685 forks source link

2024 Audit - SEC-01-010 WP4: Missing 2FA Enforcement for Sensitive Operations #7289

Open zenmonkeykstop opened 3 weeks ago

zenmonkeykstop commented 3 weeks ago

The SecureDrop Journalist application permits users to configure two-factor authentication, but it is not enforced for various security-sensitive admin operations. If an admin password and session token are leaked, an attacker could alter passwords or disable MFA for registered users without an MFA code. This issue is not a vulnerability but a hardening recommendation to strengthen authentication security.

We will be investigating this further as part of ongoing work on MFA improvements.