Authlib(v1.7.2 及以下版本)存在签名验证绕过漏洞。 方法在接收一个 JSON 序列化格式的 JWS(JSON Web Signature)对象时,会在未进行签名验证且未要求提供加密密钥的情况下,直接返回有效载荷(payload),并标记为验证成功。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet