Skip to content

2FA Can Be Removed Without a Security Check #27690

Open
@ZaxLofful

Description

@ZaxLofful

Description

A User is able to remove 2FA without an additional security check.

Standard practice here dictates that, if the user has 2FA already enabled; they should not be able to disable it without a 2FA check.

This would mean someone could have 2FA disabled, just by leaving their browser open for a few seconds.

This is for an admin account, in the event of a loss; recovery keys will need to be used.

Gitea Version

1.20

Can you reproduce the bug on the Gitea demo site?

Yes

Log Gist

No response

Screenshots

No response

Git Version

No response

Operating System

No response

How are you running Gitea?

Podman

Database

PostgreSQL

Metadata

Metadata

Assignees

No one assigned

    Labels

    topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!type/bug

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions