How to reproduce
- Login at wikitech
- Get your 2FA token
- Copy the token
- Login at horizon
- Use the same token
It works in the inversed order too, e.g.:
Login to horizon, and use the same token at wikitech
I don't know, how long this is possible, but it has a big abuse potencial: Steal the 2FA token from a user, login into the other instance, and change his settings.