Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rcm4-jv5g-wccm

Опубликовано: 07 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

zfr authentication adapter did not verify validity of tokens

Previous to @2ca5bb1c2f11537be8f94ca6867d8d69789e744a (release 0.1.2), tokens weren't checked for validity/expiration.

This potentially caused a security issue if expired tokens were not deleted after the expiration time was past, allowing anyone to still use invalidated authentication credentials.

Пакеты

Наименование

zfr/zfr-oauth2-server-module

composer
Затронутые версииВерсия исправления

< 0.1.2

0.1.2

7.5 High

CVSS3

Дефекты

CWE-613

7.5 High

CVSS3

Дефекты

CWE-613