Описание
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests with the same parent refresh token to pass the revoked check and create forked refresh-token families; the vulnerable range also includes embedded better-auth plugin versions before 1.6.0. This issue is fixed in version 1.6.11.
Уязвимые конфигурации
Конфигурация 1Версия от 1.6.0 (включая) до 1.6.11 (исключая)Версия от 1.4.9 (включая) до 1.6.11 (исключая)
Одно из
cpe:2.3:a:better-auth:better-auth\/oauth-provider:*:*:*:*:*:node.js:*:*
cpe:2.3:a:better-auth:better_auth:*:*:*:*:*:node.js:*:*
cpe:2.3:a:better-auth:better_auth:1.4.8:-:*:*:*:node.js:*:*
cpe:2.3:a:better-auth:better_auth:1.4.8:beta7:*:*:*:node.js:*:*
EPSS
Процентиль: 36%
0.00422
Низкий
8.1 High
CVSS3
Дефекты
CWE-362
Связанные уязвимости
CVSS3: 8.1
github
3 месяца назад
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
EPSS
Процентиль: 36%
0.00422
Низкий
8.1 High
CVSS3
Дефекты
CWE-362