{ "id": "CVE-2024-52586", "sourceIdentifier": "security-advisories@github.com", "published": "2024-12-09T19:15:13.707", "lastModified": "2024-12-09T19:15:13.707", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's built-in multifactor authentication mechanism. An attacker who can authenticate locally (by knowing or guessing the password of a user) can thus log in regardless of MFA requirements. This does not affect MFA that are performed by single sign-on services. Users are advised to upgrade to at least version 5.1.9 to receive a fix." }, { "lang": "es", "value": "eLabFTW es un cuaderno de laboratorio electr\u00f3nico de c\u00f3digo abierto para laboratorios de investigaci\u00f3n. Se ha encontrado una vulnerabilidad a partir de la versi\u00f3n 4.6.0 y anteriores a la versi\u00f3n 5.1.0 que permite a un atacante eludir el mecanismo de autenticaci\u00f3n multifactor integrado de eLabFTW. Un atacante que pueda autenticarse localmente (conociendo o adivinando la contrase\u00f1a de un usuario) puede iniciar sesi\u00f3n independientemente de los requisitos de autenticaci\u00f3n multifactor. Esto no afecta a la autenticaci\u00f3n multifactor que se realiza mediante servicios de inicio de sesi\u00f3n \u00fanico. Se recomienda a los usuarios que actualicen al menos a la versi\u00f3n 5.1.9 para recibir una soluci\u00f3n." } ], "metrics": { "cvssMetricV31": [ { "source": "security-advisories@github.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" }, "exploitabilityScore": 2.8, "impactScore": 2.5 } ] }, "weaknesses": [ { "source": "security-advisories@github.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-288" }, { "lang": "en", "value": "CWE-303" } ] } ], "references": [ { "url": "https://github.com/elabftw/elabftw/security/advisories/GHSA-pvxr-39g3-m28c", "source": "security-advisories@github.com" } ] }