| id: GO-2024-3160 | |
| modules: | |
| - module: github.com/ory/kratos | |
| versions: | |
| - fixed: 1.3.0 | |
| vulnerable_at: 1.3.0-pre.0 | |
| summary: |- | |
| Ory Kratos's setting required_aal `highest_available` does not properly respect | |
| code + mfa credentials in github.com/ory/kratos | |
| cves: | |
| - CVE-2024-45042 | |
| ghsas: | |
| - GHSA-wc43-73w7-x2f5 | |
| references: | |
| - advisory: https://github.com/ory/kratos/security/advisories/GHSA-wc43-73w7-x2f5 | |
| source: | |
| id: GHSA-wc43-73w7-x2f5 | |
| created: 2024-09-26T14:13:19.945453-04:00 | |
| review_status: UNREVIEWED |