CyberRota Analysis
AI-GeneratedThe Sync-in Server platform, prior to version 2.4.0, is vulnerable due to its authentication mechanism that allows attackers to bypass two-factor authentication (2FA) using stolen credentials when accessing the `POST /api/auth/token` endpoint. This flaw can lead to unauthorized access, as it grants full access and refresh JWTs without verifying if 2FA is enabled for the account. Organizations using affected versions should prioritize upgrading to 2.4.0 to mitigate the risk of credential theft and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker with stolen or phished credentials can bypass 2FA in a single request. The parallel login endpoint (`POST /api/auth/login`) correctly enforces 2FA by calling `setCookies(user, res, true)`, which gates on `user.twoFaEnabled`. Version 2.4.0 patches the issue.