Back

MEDIUM

zcap has incomplete expiration checks in capability chains.

Published Apr 10, 2024

Description

`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date` param. This can allow invocations outside of the original intended time period. A zcap still cannot be invoked without being able to use the associated private key material. `@digitalbazaar/zcap` v9.0.1 fixes expiration checking. As a workaround, one may revoke a zcap at any time.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 10, 2024
Updated Aug 2, 2024
Reserved Apr 8, 2024
CISA Vulnrichment
Updated May 14, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Apr 10, 2024
Updated Aug 2, 2024
Exploited since n/a
EUVD-2024-1217 GHSA-HP8H-7X69-4WMV