CVE-2024-8796 affects Devise-Two-Factor versions 2.2.0 through 5.x, where the default configuration generates TOTP shared secrets that are 120 bits, falling short of the 128-bit minimum specified by RFC 4226. This vulnerability, rated Medium with a CVSS score of 5.3, could allow an attacker to more easily guess the shorter shared secret and generate valid multi-factor authentication codes, leading to unauthorized access. The attack complexity is high, and it requires low privileges, but no user interaction. Currently, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 6.0.0CPE matchmatch criteria | cpe:2.3:a:tinfoilsecurity:devise-two-factor:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:tinfoilsecurity:devise-two-factor:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.