漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ignored storage errors on token revokation in ORY Fosite
Vulnerability Description
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.34.0, the `TokenRevocationHandler` ignores errors coming from the storage. This can lead to unexpected 200 status codes indicating successful revocation while the token is still valid. Whether an attacker can use this for her advantage depends on the ability to trigger errors in the store. This is fixed in version 0.34.0
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
对异常条件的处理不恰当
Vulnerability Title
ORY Fosite 代码问题漏洞
Vulnerability Description
ory ORY Fosite是ory公司的一款GO语言编写的OAUTH、OPENID连接框架。 ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) 0.34.0之前版本存在安全漏洞,该漏洞来源于TokenRevocationHandler”会忽略来自存储的错误,该漏洞允许攻击者在令牌仍然有效时成功撤消了操作。
CVSS Information
N/A
Vulnerability Type
N/A