Логотип exploitDog
bind:CVE-2025-4643
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-4643

Количество 2

Количество 2

nvd логотип

CVE-2025-4643

5 месяцев назад

Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed). This issue has been fixed in version 3.44.0 of Payload.

EPSS: Низкий
github логотип

GHSA-5v66-m237-hwf7

5 месяцев назад

Payload does not invalidate JWTs after log out

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-4643

Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed). This issue has been fixed in version 3.44.0 of Payload.

0%
Низкий
5 месяцев назад
github логотип
GHSA-5v66-m237-hwf7

Payload does not invalidate JWTs after log out

0%
Низкий
5 месяцев назад

Уязвимостей на страницу