PT-2026-67877 · Baserow · Baserow
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Baserow versions prior to 2.3.3
Description
An issue in the 2FA Verify Endpoint allows for improper authentication via remote manipulation. The flaw exists within the
verify() function located in the backend/src/baserow/api/two factor auth/views.py file. This attack is characterized by high complexity and is difficult to exploit.Recommendations
Upgrade to version 2.3.3.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Baserow