Lucene search

K

Yubikey One Time Password Validation Server Security Vulnerabilities

cve
cve

CVE-2020-10184

The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; ...

7.5CVSS

7.8AI Score

0.002EPSS

2020-03-05 11:15 PM
124
cve
cve

CVE-2020-10185

The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT aff...

8.6CVSS

8.2AI Score

0.007EPSS

2020-03-05 11:15 PM
126