Description
Punk::Plugin::TOTP versions before 0.05 for Perl accept another account-s recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted code-s digest alone, across every user-s rows, so the ownership test that follows is the only thing binding a code to the account it was issued to. That test compares the row-s user_id with the challenged user-s id through Perl-s integer coercion, and an identifier with no leading digits coerces to zero, so any two of them compare equal. User models keyed on a username, an email address or a UUID hit that case, and a numeric key compares as intended. The challenge route feeds a submitted value to the helper once TOTP verification fails, so an attacker who knows a victim-s password and holds a recovery code of their own passes the victim-s second factor.
- Published
- 2026-08-25 22:17:06
- Affected versions
- <0.05
- Type
- Library
- Last modified
- 2026-08-26 20:18:02
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H