auth_login_plusThis module provides TOTP-based two-factor authentication (2FA) for Drupal.
The module doesn't enforce the second factor when a user logs in with Drupal core's one-time login link.
This vulnerability is mitigated by the fact that an attacker must have access to a valid one-time login link for a victim's account.
Install the latest version:
- If you use the Authenticator Login Plus (2FA) module for Drupal 10 or 11, upgrade to Authenticator Login Plus (2FA) 1.0.1.
After upgrading, users with 2FA enabled will be asked for their verification code after using a one-time login link.
- Swan Kalata (akalata) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team