Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Guardian.revoke/3 acts on unverified token claims, allowing forged-token session revocation
Vulnerability Description
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token.
Guardian.revoke/3 in lib/guardian.ex decodes the supplied token with peek/1, which performs no signature verification (it only base64-decodes the JWT header and payload). The resulting unverified claims are forwarded directly to the configured token module's revoke callback and the implementation's on_revoke callback, a state-mutating sink. The sibling operations refresh/2 and exchange/4 both call decode_and_verify first, so the signature is checked before anything acts on the claims; revoke/3 is the only state-mutating path that acts on claims without verifying the signature.
An attacker who knows or guesses a victim's identifying claim values (jti, sub) can forge a JWT carrying those claims, sign it with an arbitrary key, and submit it to any endpoint that funnels a caller-supplied token into Guardian.revoke/3 (the standard logout / session-revocation pattern). When the token module mutates state keyed by the claims (whitelist deletion or blacklist insertion, for example a GuardianDb-style store), the victim's legitimate session is evicted. This is an unauthenticated session-revocation denial of service; the attacker never needs the signing secret.
This issue affects guardian: from 1.0.0 before 2.4.1.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
ueberauth Guardian 加密问题漏洞
Vulnerability Description
ueberauth Guardian是ueberauth组织开源的一个基于令牌的身份验证库,可用于 Elixir 应用程序。 ueberauth Guardian 1.0.0至2.4.1之前版本存在加密问题漏洞,该漏洞源于对加密签名验证不当,Guardian.revoke/3函数在解码令牌时未验证签名,直接处理未验证的声明,可能导致未经身份验证的攻击者利用伪造令牌撤销受害者会话,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A