MFA bypass when using silent authentication

Disclosed by
lboy's avatar
lboy
  • Engagement Undisclosed
  • Disclosed date almost 2 years ago
  • Priority P3 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by customer

Okta Customer Identity Cloud (formerly Auth0) would like to thank the TrueLayer security team and the researcher for their collaboration in discussing and identifying the specific conditions resulting in the issue, and for the camaraderie shown among our teams during the remediation efforts.

We look forward to the continued partnership. Thank you for helping us keep the Auth0 product secure.

Summary by lboy

A security researcher discovered a way to bypass MFA in the login action of TrueLayer's Console when using a known username/password. The bug was only present when certain conditions were met, with the silent authentication feature enabled. The TrueLayer security team reproduced the issue in both TrueLayer's tenant and in other tenants, and therefore determined that it was most likely a bug in Auth0's implementation. After working with the Auth0 security team and HackerOne triagers, Auth0 were able to reproduce it and roll out a fix.

Activity
  1. gw_auth0_security’s avatar
    gw_auth0_security Customer published the disclosure report

    ()

  2. lboy’s avatar
    lboy sent a message

    ()

  3. lboy’s avatar
    lboy updated the disclosure summary

    ()

  4. gw_auth0_security’s avatar
    gw_auth0_security Customer sent a message

    ()

  5. lboy’s avatar
    lboy requested disclosure

    ()

  6. aa_auth0_security’s avatar
    aa_auth0_security Customer sent a message

    ()

  7. lboy’s avatar
    lboy sent a message

    ()

  8. mp_auth0_security’s avatar
    mp_auth0_security Customer sent a message

    ()

  9. mp_auth0_security’s avatar
    mp_auth0_security Customer changed the state to Resolved

    ()

  10. lboy’s avatar
    lboy sent a message

    ()

  11. mp_auth0_security’s avatar
    mp_auth0_security Customer sent a message

    ()

  12. mp_auth0_security’s avatar
    mp_auth0_security Customer changed the state to Unresolved

    ()

  13. lboy’s avatar
    lboy sent a message

    ()

  14. lboy’s avatar
    lboy resolved a blocker for Bugcrowd Operations by providing information on reproduction

    ()

  15. lboy’s avatar
    lboy sent a message

    ()

  16. soheesec_bugcrowd’s avatarbugcrowd logo
    soheesec_bugcrowd created a blocker on the researcher to provide information on reproduction

    ()

  17. soheesec_bugcrowd’s avatarbugcrowd logo
    soheesec_bugcrowd sent a message

    ()

  18. lboy’s avatar
    lboy sent a message

    ()

  19. lboy’s avatar
    lboy claimed the submission

    ()

  20. External Submission Form’s avatar
    External Submission Form created the submission

    ()