← volver
CVE-2026-32725

SciTokens C++: Relative Path Traversal Vulnerability

CVSS 8.3 HIGHEPSS 0.8%CWE-23
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before authorization and collapses ".." path components instead of rejecting them. As a result, an attacker can use parent-directory traversal in the scope claim to broaden the effective authorization beyond the intended directory. This issue has been patched in version 1.4.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Productos afectados
scitokens · scitokens-cpp

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →