PT-2024-40456 · Unknown · Zfr-Oauth2-Server-Module

Published

2024-06-07

·

Updated

2024-06-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions zfr-oauth2-server-module versions prior to 0.1.2
Description The issue concerns the validation and expiration of tokens. Prior to the specified version, tokens were not checked for validity or expiration, potentially leading to a security issue. If expired tokens were not deleted after their expiration time, it could allow unauthorized use of invalidated authentication credentials.
Recommendations For versions prior to 0.1.2, update to version 0.1.2 or later to ensure that tokens are properly checked for validity and expiration. As a temporary workaround, consider manually deleting expired tokens to minimize the risk of exploitation.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-RCM4-JV5G-WCCM

Affected Products

Zfr-Oauth2-Server-Module