Enable 2Fa verification without verifying email
Medium
C
Cloudflare Public Bug Bounty
Submitted None
Team Summary
Official summary from Cloudflare Public Bug Bounty
It was possible to enable Two-factor authentication feature for an unverified Cloudflare account . As a consequence, a legitimate owner of the e-mail address, which was used to create the unverified account, is unable to log in or reset password to the Cloudflare account. The issue was fixed by the Engineering team by implementing access control restrictions on 2FA configuration for unverified accounts.
Actions:
Reported by
motu-vai
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic