A leaked password reset link could be used to skip two-factor authentication

Affected versions

  • Kimai versions <= 2.67.0 are affected by this security issue
  • The issue has been fixed in Kimai 2.68.0
  • Severity: Medium
  • A CVE ID is requested, pending assignment

Description

If someone got hold of a password reset link that was sent to a user, they could turn it into a “stay logged in” cookie and access that user’s account without entering the two-factor authentication (2FA) code. Two-factor authentication is meant to protect an account even when the first login step is compromised, so this weakened the protection for every user who relies on it, including administrators.

  • The attacker needs to obtain a valid, unexpired password reset link for the targeted user, e.g. from a compromised mailbox.
  • All Kimai installations with the password reset feature enabled are affected, which is the default.
  • The cause is that password reset links and “stay logged in” cookies were signed with the same secret key, so Kimai accepted the reset link’s signature as a valid cookie.
  • Kimai treated the resulting session like a remembered browser and didn’t ask for the 2FA code.
  • For users without 2FA, a leaked reset link grants access by design, the additional risk applies to 2FA enabled accounts.

Solution

The “Remember me” cookies now use their own secret key and different signature data, so a password reset link can no longer be used as a cookie. Additionally, Kimai 2.69.0 always asks for the 2FA code when someone logs in through a password reset link.

Upgrading invalidates all existing “remember me” cookies, so every user needs to log in once again.

Users should update to 2.68.0 or newer.

Credits

  • Reported by: Tan-JunWei
  • Patched by: kevinpapst
Top