The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://drupal.org/node/1995634 | patch |
http://www.securityfocus.com/bid/59884 | vdb entry |
https://drupal.org/node/1995706 | patch vendor advisory |
https://drupal.org/node/1995482 | patch |