← Back
Web Application
CVE-2026-54418 high CVSS 8.1

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...

Summary

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...

AI summary openai / gpt-4o

Leantimeのバージョン3.6.2までのシステムでは、所有者確認なしに任意のユーザーIDを指定してJSON-RPCメソッドが操作できます。これにより、任意のユーザーの2要素認証を解除したり、TOTP秘密を読み取ることができます。この欠陥により、2FA保護が無効となる可能性があります。
❓ What is the problem
所有者確認なしにJSON-RPCメソッドの操作が可能な脆弱性。
📍 Affected scope
Leantime 3.6.2までのバージョン。
🔥 Severity
任意のユーザーの2FAを無効化できるため、アカウント保護が完全に無効化される。
🔧 How to fix
JSON-RPCメソッドに所有者確認と権限属性ゲートを追加する。
🛡️ Workaround
現時点では情報なし。
🔍 Detection
認証ユーザーが無効な2FA操作を行った痕跡をログで確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →