9.0.1
2 years ago
8 months ago
Known vulnerabilities in the @digitalbazaar/zcap package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@digitalbazaar/zcap is an Authorization Capabilities reference implementation. Affected versions of this package are vulnerable to Insufficient Session Expiration due to incomplete expiration checks in capability chains. When invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the How to fix Insufficient Session Expiration? Upgrade | <9.0.1 |