GHSA-rqg8-xjp2-pg9w
CRITICALCVE-2019-12887LinOTP is prone to a replay attack with activated automatic resynchronization. This vulnerability may allow an attacker to successfully log in with OTP values recorded at a previous point in time.
- Affected
- >= 0, < 2.11.1
- Fixed in
- 2.11.1
- Weakness
- CWE-294
- Published
- 2022-05-24
- Source
- github