eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check
If the resolver parameter is passed, but the user does not exist, all failcounters of tokens in that resolver will be increased.
This, along with other issues, was fixed in eduMFA v2.9.1.
Limiting access to /validate/check to client applications (i.e. Shibboleth/FreeRADIUS) using an authorization policy with api_key_required or using e.g. the reverse proxy.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 65.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 65.00 |
VPI 공식 vpi-v1 기준