OSV 1.4.0 · unreviewed · 修改于 2026-08-25 20:31
发布时间
2026-08-25 20:31
GitHub 审查时间
—
NVD 发布时间
2026-08-25 20:16
源文件
advisories/unreviewed/2026/08/GHSA-3r5q-vfpj-wprr/GHSA-3r5q-vfpj-wprr.json
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on nil ExpiresAt field, RevokeToken skips when remainTTL is zero, and admin delete does not blacklist the JTI, leaving stolen tokens cryptographically valid until JWT secret rotation.
该公告没有提供结构化的受影响软件包信息。