Skip to content

zcap has incomplete expiration checks in capability chains.

Moderate severity GitHub Reviewed Published Apr 10, 2024 in digitalbazaar/zcap • Updated Apr 21, 2024

Package

npm @digitalbazaar/zcap (npm)

Affected versions

< 9.0.1

Patched versions

9.0.1

Description

Impact

When invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the expires property is not properly checked against the current date or other date param. This can allow invocations outside of the original intended time period. A zcap still cannot be invoked without being able to use the associated private key material.

Patches

@digitalbazaar/zcap v9.0.1 fixes expiration checking.

Workarounds

A zcap could be revoked at any time.

References

digitalbazaar/zcap#82

References

@davidlehn davidlehn published to digitalbazaar/zcap Apr 10, 2024
Published to the GitHub Advisory Database Apr 10, 2024
Reviewed Apr 10, 2024
Published by the National Vulnerability Database Apr 10, 2024
Last updated Apr 21, 2024

Severity

Moderate
4.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CVE ID

CVE-2024-31995

GHSA ID

GHSA-hp8h-7x69-4wmv

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.