Executive brief
Ajenti plugin core allows attackers to bypass password authentication when two-factor authentication (2FA) is enabled. This vulnerability affects versions prior to 0.112 and is resolved in the 0.112 release.
Affected products
- ajenti ajenti_plugin_core
- PyPI ajenti-plugin-core