CVE-2024-31995

`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date` param. This can allow invocations outside of the original intended time period. A zcap still cannot be invoked without being able to use the associated private key material. `@digitalbazaar/zcap` v9.0.1 fixes expiration checking. As a workaround, one may revoke a zcap at any time.
Configurations

No configuration.

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://github.com/digitalbazaar/zcap/commit/261eea040109b6e25159c88d8ed49d3c37f8fcfe - () https://github.com/digitalbazaar/zcap/commit/261eea040109b6e25159c88d8ed49d3c37f8fcfe -
References () https://github.com/digitalbazaar/zcap/commit/55f8549c80124b85dfb0f3dcf83f2c63f42532e5 - () https://github.com/digitalbazaar/zcap/commit/55f8549c80124b85dfb0f3dcf83f2c63f42532e5 -
References () https://github.com/digitalbazaar/zcap/pull/82 - () https://github.com/digitalbazaar/zcap/pull/82 -
References () https://github.com/digitalbazaar/zcap/security/advisories/GHSA-hp8h-7x69-4wmv - () https://github.com/digitalbazaar/zcap/security/advisories/GHSA-hp8h-7x69-4wmv -
Summary
  • (es) `@digitalbazaar/zcap` proporciona una implementación de referencia de JavaScript para capacidades de autorización. Antes de la versión 9.0.1, al invocar una capacidad con una profundidad de cadena de 2, es decir, se delega directamente desde la capacidad raíz, la propiedad "expires" no se verifica adecuadamente con la fecha actual u otro parámetro de "fecha". Esto puede permitir invocaciones fuera del período de tiempo previsto original. Aún no se puede invocar un zcap sin poder utilizar el material de clave privada asociado. `@digitalbazaar/zcap` v9.0.1 corrige la verificación de vencimiento. Como workaround, se puede revocar un zcap en cualquier momento.

10 Apr 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-10 22:15

Updated : 2024-11-21 09:14


NVD link : CVE-2024-31995

Mitre link : CVE-2024-31995

CVE.ORG link : CVE-2024-31995


JSON object : View

Products Affected

No product.

CWE
CWE-613

Insufficient Session Expiration