PT-2024-40456 · Unknown · Zfr-Oauth2-Server-Module
Published
2024-06-07
·
Updated
2024-06-07
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
zfr-oauth2-server-module versions prior to 0.1.2
Description
The issue concerns the validation and expiration of tokens. Prior to the specified version, tokens were not checked for validity or expiration, potentially leading to a security issue. If expired tokens were not deleted after their expiration time, it could allow unauthorized use of invalidated authentication credentials.
Recommendations
For versions prior to 0.1.2, update to version 0.1.2 or later to ensure that tokens are properly checked for validity and expiration. As a temporary workaround, consider manually deleting expired tokens to minimize the risk of exploitation.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zfr-Oauth2-Server-Module