
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity authentication bypass vulnerability was identified in the otpauth npm package (GHSA-rmmc-8cqj-hfp3), affecting versions prior to 3.2.8. The vulnerability was discovered and reviewed on August 31, 2020, published to the GitHub Advisory Database on September 3, 2020, and last updated on January 9, 2023. The issue impacts the authentication mechanism of the otpauth package, which is widely used for implementing One-Time Password (OTP) authentication (GitHub Advisory).
The vulnerability stems from a flaw in the totp.validate() function implementation within the otpauth package. The function incorrectly validates single-digit tokens, potentially returning positive values for invalid tokens. This vulnerability is classified under CWE-287 (Improper Authentication) and has been assigned a high severity rating (GitHub Advisory).
The vulnerability allows potential attackers to bypass OTP authentication mechanisms by submitting single-digit tokens, even when these tokens are invalid. This compromises the security of systems implementing OTP authentication using affected versions of the otpauth package (GitHub Advisory).
The vulnerability can be exploited by submitting single-digit tokens to bypass the OTP authentication mechanism. The simplicity of the exploit method makes this vulnerability particularly concerning for affected systems (GitHub Advisory).
Users are strongly advised to upgrade to otpauth version 3.2.8 or later, which contains the fix for this vulnerability. This is the primary and recommended mitigation strategy (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."