漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Token Invalidation in WSO2 Identity Server Allows Access After Account Lock
Vulnerability Description
Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequence is that a locked user account can maintain access to protected resources through the use of existing, unexpired access tokens. This creates a security gap where access control policies are bypassed, potentially leading to unauthorized data access or actions until the tokens naturally expire.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
WSO2 Identity Server 安全漏洞
Vulnerability Description
WSO2 Identity Server(IS)是美国WSO2公司的一款身份认证服务器。 WSO2 Identity Server存在安全漏洞,该漏洞源于用户账户被锁定时未撤销活动访问令牌,可能导致绕过访问控制策略。
CVSS Information
N/A
Vulnerability Type
N/A