OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:59
发布时间
2020-09-05 01:29
GitHub 审查时间
2020-09-01 02:59
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-v66p-w7qx-wv98/GHSA-v66p-w7qx-wv98.json
All versions of express-laravel-passport are vulnerable to an Authentication Bypass. The package fails to properly validate JWTs, allowing attackers to send HTTP requests impersonating other users.
Upgrade to version 2.0.5 or later.