以下是该漏洞描述信息的中文翻译: --- 不当认证漏洞(Improper Authentication) 在 中,存在一个漏洞,允许将具有用途限制(purpose-limited)的 JWT 令牌在状态无感知(stateless)的 bearer-token 验证场景下被重放(replayed)为完整的 bearer API 凭据。 这个 bearer-token 认证助手会验证 JWT 的签名,并拒绝包含 声明的令牌,但它在 bearer 边界处并未检查令牌的 声明是否等于 。当资源配置为 (DSL 默认值)时,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| team-alembic | ash_authentication | 3.10.5< 4.14.2 |
affected |
5.0.0-rc.0< 5.0.0-rc.13 |
affected | ||
eca8cadea0f1595ed2c10a0c177b1da9aa9e5269< * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| team-alembic | ash_authentication | 3.10.5 ~ 4.14.2 |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| team-alembic | ash_authentication | eca8cadea0f1595ed2c10a0c177b1da9aa9e5269 ~ * |
cpe:2.3:a:team-alembic:ash_authentication:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet