In SFTPGO 2.6.2, the JWT implementation lacks cerrtain security measures, such as using JWT ID (JTI) claims, nonces, and proper expiration and invalidation mechanisms.
References
Link | Resource |
---|---|
https://alexsecurity.rocks/posts/cve-2024-40430/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-07-22 07:15
Updated : 2024-07-25 17:07
NVD link : CVE-2024-40430
Mitre link : CVE-2024-40430
CVE.ORG link : CVE-2024-40430
JSON object : View
Products Affected
sftpgo_project
- sftpgo
CWE
CWE-639
Authorization Bypass Through User-Controlled Key