Django Mfa2 Project is a focused authentication library providing multi-factor authentication capabilities for Django applications; its narrow product scope and deployment model as a middleware component presents a limited and developer-controlled attack surface. The recorded vulnerability signal centers on the authentication abstraction layer itself. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Django Mfa2 Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42731HIGH mfa/FIDO2.py in django-mfa2 before 2.5.1 and 2.6.x before 2.6.1 allows a replay attack that could be used to register another device for a user. The device registration challenge i | Oct 11, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Django Mfa2 Project.
Media articles that mention a CVE ID that affects a product developed by Django Mfa2 Project — matched by CVE ID, not by vendor name.