blob: a230401da1ce4cc6f0bff1fcf38f575af8f4c87b [file] [log] [blame]
id: GO-2024-3160
modules:
- module: github.com/ory/kratos
versions:
- fixed: 1.3.0
vulnerable_at: 1.3.0-pre.0
summary: |-
Ory Kratos's setting required_aal `highest_available` does not properly respect
code + mfa credentials in github.com/ory/kratos
cves:
- CVE-2024-45042
ghsas:
- GHSA-wc43-73w7-x2f5
references:
- advisory: https://github.com/ory/kratos/security/advisories/GHSA-wc43-73w7-x2f5
source:
id: GHSA-wc43-73w7-x2f5
created: 2024-09-26T14:13:19.945453-04:00
review_status: UNREVIEWED