Two-factor authentication could be skipped by another logged-in user

Affected versions

  • Kimai versions > 2.0 are affected by this security issue
  • The issue has been fixed in Kimai 2.68.0
  • Severity: High
  • A CVE ID is requested, pending assignment

Description

If someone was already logged in to Kimai and knew the password of another account, they could log in to that account without being asked for its two-factor authentication (2FA) code. Two-factor authentication is meant to protect an account even when the password is known, so this weakened the protection for every user who relies on it, including administrators.

  • The attacker needs an account on the same Kimai installation, any role works and no own 2FA setup are required.
  • The attacker needs to know the password of the targeted account.
  • The cause is the “stay logged in” feature: if a browser was still remembered from an earlier login, Kimai skipped the 2FA code for any login from that browser, instead of only for the user who was remembered.
  • The targeted user doesn’t need to do anything, never sees a 2FA prompt, and their own 2FA settings stay unchanged, so nothing points to the account being accessed, except for the last-login date.
  • After a successful login, the attacker holds a normal session and a new “stay logged in” cookie for the targeted account, which keeps access alive for up to seven days.

Solution

Kimai now skips the 2FA code only for the same user who was remembered before. Switching to another account from a remembered browser still works, but that account’s 2FA code is now always requested.

Users should update to 2.68.0 or newer.

Credits

  • Reported by: AzureADTrent
  • Patched by: kevinpapst
Top