Loading HuntDB...

2FA BYPASS

High
C
Cloudflare Public Bug Bounty
Submitted None

Team Summary

Official summary from Cloudflare Public Bug Bounty

Cloudflare's Dashboard enables users to configure 2-Factor Authentication using a Security Key. An issue in the authentication system allowed for the retrieval of recovery codes (used to regain account access if the security key is lost) after verifying the username and password but before completing the authentication process by touching the Security Key. Cloudflare's Engineering team resolved the issue by disallowing requests to the vulnerable API endpoint until users are fully authenticated.

Reported by imtheking

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic