ueberauth Ueberauth Apple是ueberauth组织开源的一款Apple账户认证策略模块。 Ueberauth Apple 0.1.0版本至0.6.2之前版本存在授权问题漏洞,该漏洞源于Ueberauth.Strategy.Apple.Token.payload/2函数未验证注册声明(包括iss、aud、exp、iat和sub声明),可能导致攻击者伪造身份验证,通过获取Apple签名的ID令牌实现账户接管。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| ueberauth | ueberauth_apple | 0.1.0< 0.6.2 |
affected |
3908a187d045c75994b62ce340c3aa26bb8976b8< 01e2d9c9b3134e1b78633ad82d136d5ff4a61f28 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| ueberauth | ueberauth_apple | 0.1.0 ~ 0.6.2 |
cpe:2.3:a:ueberauth:ueberauth_apple:*:*:*:*:*:*:*:*
|
|
| ueberauth | ueberauth_apple | 3908a187d045c75994b62ce340c3aa26bb8976b8 ~ 01e2d9c9b3134e1b78633ad82d136d5ff4a61f28 |
cpe:2.3:a:ueberauth:ueberauth_apple:*:*:*:*:*:*:*:*
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC暂无评论