PT-2026-29184 · Scitokens · Scitokens
Pmcao
·
Publicado
2026-03-31
·
Atualizado
2026-04-04
·
CVE-2026-32716
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SciTokens versions prior to 1.9.6
Description
SciTokens is a library for generating and using SciTokens. The Enforcer component incorrectly validates scope paths using a simple prefix match, allowing a token with access to a specific path to also access sibling paths that share the same prefix. This results in an Authorization Bypass. The issue occurs because the
startswith method is used for scope path validation, which is insufficient for secure access control. The vulnerable component is the Enforcer.Recommendations
Update to SciTokens version 1.9.6 or later.
Exploit
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Scitokens