VDB
Sign up
MEDIUM4.3

GHSA-hp8h-7x69-4wmv

zcap has incomplete expiration checks in capability chains.

Quick fix

GHSA-hp8h-7x69-4wmv — @digitalbazaar/zcap: upgrade to the fixed version with the command below.

npm install @digitalbazaar/zcap@9.0.1

Details

### Impact

When invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date` param. This can allow invocations outside of the original intended time period. A zcap still cannot be invoked without being able to use the associated private key material.

### Patches

`@digitalbazaar/zcap` v9.0.1 fixes expiration checking.

### Workarounds

A zcap could be revoked at any time.

### References

https://github.com/digitalbazaar/zcap/pull/82

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@digitalbazaar/zcap
Introduced in: 0Fixed in: 9.0.1
Fixnpm install @digitalbazaar/zcap@9.0.1

References