Skip to content

[GHSA-29r8-gvx4-r9w3] Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)#7233

Merged
advisory-database[bot] merged 1 commit intomainfrom
MrSilaz-GHSA-29r8-gvx4-r9w3
Mar 25, 2026
Merged

[GHSA-29r8-gvx4-r9w3] Authentication Bypass in extension "E-Mail MFA Provider" (mfa_email)#7233
advisory-database[bot] merged 1 commit intomainfrom
MrSilaz-GHSA-29r8-gvx4-r9w3

Conversation

@MrSilaz
Copy link
Copy Markdown
Contributor

@MrSilaz MrSilaz commented Mar 25, 2026

Updates

  • Affected products

Comments
The vulnerability has been addressed in the following releases:

v2.0.1: https://github.com/MrSilaz/mfa_email/releases/tag/v2.0.1
v1.0.7: https://github.com/MrSilaz/mfa_email/releases/tag/v1.0.7

The patched versions should be updated to >= 1.0.7 and >= 2.0.1 accordingly.

@advisory-database advisory-database bot merged commit 67fc64d into main Mar 25, 2026
3 checks passed
@advisory-database
Copy link
Copy Markdown
Contributor

Hi @MrSilaz! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the MrSilaz-GHSA-29r8-gvx4-r9w3 branch March 25, 2026 19:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant