Fedora Account System
Red Hat Associate
Red Hat Customer
MSA-26-0013: Email-based MFA bypass Description: A flaw in email-based multi-factor authentication made it possible for a user to bypass another user's MFA token check if using the email factor. Note: Valid login credentials (such as username and password) were still required to log into the account. Issue summary: Email-based MFA bypass Severity/Risk: Serious Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier unsupported versions Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12 Reported by: Brendan Heywood Issue no.: MDL-88767 CVE identifier: Pending