VYPR

PyPI package

django-two-factor-auth

pkg:pypi/django-two-factor-auth

Vulnerabilities (1)

  • CVE-2020-15105MedJul 10, 2020
    affected < 1.12fixed 1.12

    Django Two-Factor Authentication before 1.12, stores the user's password in clear text in the user session (base64-encoded). The password is stored in the session when the user submits their username and password, and is removed once they complete authentication by entering a two