Количество 2
Количество 2
CVE-2026-9094
Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.
GHSA-c9w5-qp6m-m395
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9094 Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries. | CVSS3: 9.8 | 0% Низкий | 2 месяца назад | |
GHSA-c9w5-qp6m-m395 Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check | CVSS3: 9.8 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу