org.biscuitsec:biscuit@3.0.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.biscuitsec:biscuit package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Exposure of Resource to Wrong Sphere

Affected versions of this package are vulnerable to Exposure of Resource to Wrong Sphere via the ThirdPartyBlock request process. An attacker can trick the third-party authority into generating datalog trusting the wrong keypair by forging a third-party block request with incorrect public key information.

How to fix Exposure of Resource to Wrong Sphere?

Upgrade org.biscuitsec:biscuit to version 4.0.0 or higher.

[,4.0.0)
  • L
Improper Verification of Cryptographic Signature

Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the ThirdPartyBlockRequest process, by altering the public keys field in the request, leading to trust in an incorrect keypair.

Note: This is only exploitable if the attacker can intercept and modify the ThirdPartyBlockRequest before it reaches the third-party authority.

How to fix Improper Verification of Cryptographic Signature?

Upgrade org.biscuitsec:biscuit to version 4.0.0 or higher.

[3.0.0,4.0.0)