GHSA-x72p-g37q-4xr9

Suggest an improvement
Source
https://github.com/advisories/GHSA-x72p-g37q-4xr9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x72p-g37q-4xr9
Aliases
Withdrawn
2024-07-31T18:42:56Z
Published
2024-07-22T09:31:55Z
Modified
2026-09-10T03:50:17Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Withdrawn: SFTPGo's JWT implmentation lacks certain security measures
Details

Withdrawn: The attack vector described in the backing report required that an attacker gain access to a user's session cookie. By gaining access to the session cookie the attacker is for all intents and purposes the valid user and any access to user data would be expected.

In SFTPGo 2.6.2, the JWT implementation lacks certain security measures, such as using JWT ID (JTI) claims, nonces, and proper expiration and invalidation mechanisms.

Database specific
{
    "cwe_ids":  [
        "CWE-323",
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-07-22T18:46:59Z",
    "nvd_published_at":  "2024-07-22T07:15:02Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/drakkan/sftpgo/v2

Package

Name
github.com/drakkan/sftpgo/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/drakkan/sftpgo/v2

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.6.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json"