Executive brief
Ajenti suffers from a race condition in its core plugin that allows attackers to bypass two-factor authentication (2FA) during a brief window following initial user authentication.
Affected products
- ajenti ajenti_plugin_core
- PyPI ajenti-plugin-core