GHSA-cv5x-2gg8-4hc7CriticalCVSS 9.1
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass...
🔗 CVE IDs covered (1)
📋 Description
Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.