CVE-2019-18985: Pimcore 2FA Vulnerable to Brute Forcing
9.8
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.00414%
CWE
Published
5/24/2022
Updated
8/1/2023
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| pimcore/pimcore | composer | < 6.2.2 | 6.2.2 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The critical vulnerability stems from missing brute force protection in the 2FA verification endpoint. The commit 9f2d075 adds BruteforceProtectionHandler to twoFactorAuthenticationAction, explicitly introducing attempt tracking and protection checks. The pre-patch absence of these checks in this authentication flow directly matches the CWE-307 description. The UserController.php changes (CSRF removal) are unrelated to the core brute force vulnerability.