Omnivore API(packages/api)在提交 abf53d6 修复之前,其 Apple 登录令牌验证中存在身份验证绕过漏洞。 函数会从攻击者提供的 JWT 头部中提取 字段,并将其作为唯一允许的算法传递给 。由于使用的 jsonwebtoken 版本为 v8(该版本不验证密钥与算法的兼容性),攻击者可以将 设置为 ,并使用 Apple 公开可用的 RSA 公钥作为 HMAC 密钥来签名伪造令牌,从而绕过签名验证,并冒充任意与 Apple 关联的账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| omnivore-app | omnivore | < abf53d650875 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| omnivore-app | omnivore | 0 ~ abf53d650875 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet