FreeBSD : duo -- Two-factor authentication bypass (738e8ae1-46dd-11e7-a539-0050569f7e80)
High Nessus Plugin ID 100582
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionThe duo security team reports :
An untrusted user may be able to set the http_proxy variable to an invalid address. If this happens, this will trigger the configured 'failmode' behavior, which defaults to safe. Safe mode causes the authentication to report a success.
SolutionUpdate the affected package.