Skip to content
This repository has been archived by the owner on Dec 2, 2021. It is now read-only.

Vulnerability in JWT trusted device token #143

Closed
scheb opened this issue Jul 8, 2018 · 0 comments
Closed

Vulnerability in JWT trusted device token #143

scheb opened this issue Jul 8, 2018 · 0 comments
Labels

Comments

@scheb
Copy link
Owner

scheb commented Jul 8, 2018

Before version 3.7 the bundle is vulnerable to a security issue in JWT, which can be exploited by an attacker to generate trusted device cookies on their own, effectively by-passing two-factor authentication.

Please either disable the trusted feature in your application or upgrade to a bundle version >= 3.7.

@scheb scheb closed this as completed Jul 8, 2018
@scheb scheb added the Security label Dec 5, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant