Skip to content

Do not trust SMS number from crypted token, search it again in LDAP Directory#818

Merged
coudot merged 1 commit into
1.5from
816-hijack-sms-code
Nov 22, 2023
Merged

Do not trust SMS number from crypted token, search it again in LDAP Directory#818
coudot merged 1 commit into
1.5from
816-hijack-sms-code

Conversation

@coudot

@coudot coudot commented Nov 22, 2023

Copy link
Copy Markdown
Member

Fixes #816

@coudot coudot added this to the 1.5.4 milestone Nov 22, 2023
@coudot coudot self-assigned this Nov 22, 2023
@coudot coudot changed the base branch from master to 1.5 November 22, 2023 15:05
@coudot coudot merged commit 0f353b3 into 1.5 Nov 22, 2023
@coudot coudot deleted the 816-hijack-sms-code branch November 22, 2023 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[CVE-2023-49032] Hijack SMS codes to an arbitrary phone number

1 participant