GHSA-xmh9-rg6f-j3mr
UNKNOWNAny Pod on a Solid server using a vulnerable version of the identity-token-verifier library is at risk of a spoofed Demonstration of Proof-of-Possession (DPoP) token binding. This vulnerability could give total and complete access to a targeted Pod.
- Affected
- >=0, <0.5.2
- Fixed in
- not stated
- Weakness
- CWE-290
- Published
- 2021-03-12
- Source
- osv