Описание
zfr authentication adapter did not verify validity of tokens
Previous to @2ca5bb1c2f11537be8f94ca6867d8d69789e744a (release 0.1.2), tokens weren't checked for validity/expiration.
This potentially caused a security issue if expired tokens were not deleted after the expiration time was past, allowing anyone to still use invalidated authentication credentials.
Ссылки
- https://github.com/zf-fr/zfr-oauth2-server-module/issues/6
- https://github.com/zf-fr/zfr-oauth2-server-module/commit/2ca5bb1c2f11537be8f94ca6867d8d69789e744a
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zfr/zfr-oauth2-server-module/2014-04-26.yaml
- https://github.com/zf-fr/zfr-oauth2-server-module/tree/0.1.2
Пакеты
Наименование
zfr/zfr-oauth2-server-module
composer
Затронутые версииВерсия исправления
< 0.1.2
0.1.2
7.5 High
CVSS3
Дефекты
CWE-613
7.5 High
CVSS3
Дефекты
CWE-613