In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/forgekeep/nebula-mesh/internal/api to version 0.5.0 or higher.
Affected versions of this package are vulnerable to Insufficient Session Expiration due to the POST /ui/hosts process not honoring configured enrollment token TTL settings and instead issuing tokens with a fixed 24-hour validity. An attacker can obtain enrollment tokens with a longer-than-intended validity period by creating hosts through the Web UI, increasing the risk that exposed or intercepted tokens can be used to enroll unauthorized hosts and retrieve sensitive configuration data.