Boruta 是一个独立的授权服务器,旨在实现 OAuth 2.0 和 OpenID Connect 规范,并支持去中心化身份验证标准。在 0.10.0 版本之前,Boruta 会在业务事件日志中记录敏感的 OAuth 和 OpenID Connect 值。日志中可能包含的敏感值包括:访问令牌、刷新令牌、授权码、代理令牌、直接 POST 码、ID 令牌、VP 令牌,以及提交给检查(introspection)或吊销(revocation)端点的令牌。能够访问 Boruta 日志、日志聚合系统或管理端日志查看器的攻击
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| malach-it | boruta-server | < 0.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet