Описание
@digitalbazaar/zcap provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the expires property is not properly checked against the current date or other date param. This can allow invocations outside of the original intended time period. A zcap still cannot be invoked without being able to use the associated private key material. @digitalbazaar/zcap v9.0.1 fixes expiration checking. As a workaround, one may revoke a zcap at any time.
Ссылки
EPSS
Процентиль: 36%
0.00152
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-613
Связанные уязвимости
CVSS3: 4.3
github
почти 2 года назад
zcap has incomplete expiration checks in capability chains.
EPSS
Процентиль: 36%
0.00152
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-613