Express Gateway 在 1.16.11 及更早版本中存在一个硬编码加密密钥漏洞。攻击者若具备对数据存储的访问权限,便可通过默认配置的 敏感密钥 解密已存储的 OAuth 2.0 Token 密钥。能够读取 Redis 数据的攻击者可以解密 值,并结合已存储的 Token ID,从而获取任意用户的合法 Bearer Token。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ExpressGateway | express-gateway | 0 ~ 1.16.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet