GHSA-56p6-qw3c-fq2g
LOWCVE-2025-30351Since the user status is not checked when verifying a session token a suspended user can use the token generated in session auth mode to access the API despite their status.
- Affected
- >= 11.0.7, < 13.0.0
- Fixed in
- 13.0.0
- Weakness
- CWE-672
- Published
- 2025-03-26
- Source
- github