CERT/CC Warns of Six Logto Vulnerabilities in SSO and MFA Handling
ID: 4c417baf-5f77-5b8d-abaa-be670768de20
STIX ID: report--4c417baf-5f77-5b8d-abaa-be670768de20
Feed Name: securityonline.info
Threat Score
CERT/CC disclosed six vulnerabilities in the Logto identity platform (VU#492466) that can enable account takeover, MFA bypass, token replay, and SAML assertion replay or timing bypasses; no vendor fixes or confirmed exploitation exist yet and administrators are advised to apply mitigations such as enforcing upstream MFA, avoiding email-shared local accounts, shortening sessions, and monitoring auth logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
