Critical Vulnerability in syracom AG 2FA Plugin for Atlassian Products
ID: fdaf0be6-c5d6-5190-83d6-3b7f639eb540
STIX ID: report--fdaf0be6-c5d6-5190-83d6-3b7f639eb540
Feed Name: ThreatCluster
Threat Score
The Secure Login (2FA) plugin for Atlassian products contains a broken access control flaw that enables attackers with valid user credentials to bypass multi-factor authentication by altering the HTTP User-Agent header. Successful exploitation can provide unauthorized access to administrative settings and permit disabling of 2FA across affected installations; the vendor has released a patch and immediate remediation is recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
