Junglewise Threat Intelligence

otpauth TOTP authentication bypass via single-digit tokens

Severity: info · Published 2020-09-03

Vendors: npm.

Executive brief

otpauth is a library for generating and validating one-time passwords (OTP) used to secure user accounts. A flaw in the TOTP validation function accepts invalid single-digit tokens as valid, allowing attackers to bypass OTP authentication with trivial guesses, potentially gaining unauthorized access to accounts protected by OTP.

Technical details

The vulnerability is an authentication bypass in the totp.validate() function (CWE-287: Improper Authentication). The function incorrectly returns positive (truthy) values when validating single-digit tokens, even when they are invalid. This allows an attacker to bypass TOTP authentication by submitting any single digit (0–9) as the OTP, requiring only 10 guesses to gain access. The vulnerability affects all versions prior to 3.2.8; a fix is available in version 3.2.8 and later.

Affected products

  • otpauth otpauth <3.2.8

Timeline

  • 2020-09-03: disclosed
  • 2020: patched: Version 3.2.8 fixes the vulnerability

References