No admin audit entry for enabling/disabling 2FA

Disclosed: 2021-06-16 08:40:24 By rtod To nextcloud
Low
Vulnerability Details
Related to https://hackerone.com/reports/1177353 When a user enables or disables 2FA there is no entry in the audit log. ## Impact Especially for disabling it should probably be logged there. But account security related things should be in there.
Actions
View on HackerOne
Report Stats
  • Report ID: 1200989
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report