Логотип exploitDog
bind:CVE-2020-15222
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15222

Количество 2

Количество 2

nvd логотип

CVE-2020-15222

больше 5 лет назад

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is not checked. When using client authentication method "private_key_jwt", OpenId specification says the following about assertion `jti`: "A unique identifier for the token, which can be used to prevent reuse of the token. These tokens MUST only be used once, unless conditions for reuse were negotiated between the parties". Hydra does not seem to check the uniqueness of this `jti` value. This problem is fixed in version 0.31.0.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-v3q9-2p3m-7g43

больше 4 лет назад

Token reuse in Ory fosite

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15222

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is not checked. When using client authentication method "private_key_jwt", OpenId specification says the following about assertion `jti`: "A unique identifier for the token, which can be used to prevent reuse of the token. These tokens MUST only be used once, unless conditions for reuse were negotiated between the parties". Hydra does not seem to check the uniqueness of this `jti` value. This problem is fixed in version 0.31.0.

CVSS3: 8.1
0%
Низкий
больше 5 лет назад
github логотип
GHSA-v3q9-2p3m-7g43

Token reuse in Ory fosite

CVSS3: 8.1
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу