CVE-2024-8122

CVE-2024-8122 published: The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA). This allows unused OTPs to remain valid indefinitely, presenting an opportunity for malicious actors to conduct brut...

View full NVD advisory → ← Back to CVE watch