Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls
High severity
GitHub Reviewed
Published
Nov 27, 2023
in
pimcore/admin-ui-classic-bundle
•
Updated Nov 28, 2023
Description
Published to the GitHub Advisory Database
Nov 27, 2023
Reviewed
Nov 27, 2023
Published by the National Vulnerability Database
Nov 28, 2023
Last updated
Nov 28, 2023
Impact
AdminBundle\Security\PimcoreUserTwoFactorConditionintroduced in v11 disable the two factor authentication for all non-admin security firewalls.An authenticated user can access the system without having to provide the 2 factor credentials.
Patches
Apply patch https://patch-diff.githubusercontent.com/raw/pimcore/admin-ui-classic-bundle/pull/345.patch
Workarounds
Upgrade to version 1.2.2 or apply the patch manually.
References