Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 421
Alerts This Week
Warning Icon 1 421

Ubuntu 22.04 LTS: USN-7050-1 critical: Devise-Two-Factor issues

ubuntu
Calendar Grey October 1, 2024
Scroller Ubuntu
Ubuntu has released security patches for Devise-Two-Factor addressing critical vulnerabilities; essential guidelines provided for prompt installations.
Several security issues were fixed in Devise-Two-Factor.

Summary

Several security issues were fixed in Devise-Two-Factor.

Software Description:

- ruby-devise-two-factor: Barebones two-factor authentication with Devise

Details:

Benoit Côté-Jodoin and Michael Nipper discovered that Devise-Two-Factor

incorrectly handled one-time password validation. An attacker could

possibly use this issue to intercept and re-use a one-time password.

(CVE-2021-43177)

Garrett Rappaport discovered that Devise-Two-Factor incorrectly handled

generating multi-factor authentication codes. An attacker could possibly

use this issue to generate valid multi-factor authentication codes.

(CVE-2024-8796)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
   ruby-devise-two-factor          4.0.0-2ubuntu0.1~esm1
                                   Available with Ubuntu Pro

Ubuntu 20.04 LTS
   ruby-devise-two-factor          3.1.0-2ubuntu0.1~esm1
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7050-1

  CVE-2021-43177, CVE-2024-8796

Severity
critical
Lowest
Low
Medium
High
Critical

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.