GHSA-hp8h-7x69-4wmv
zcap has incomplete expiration checks in capability chains.
Quick fix
GHSA-hp8h-7x69-4wmv — @digitalbazaar/zcap: upgrade to the fixed version with the command below.
npm install @digitalbazaar/zcap@9.0.1Details
### Impact
When invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date` param. This can allow invocations outside of the original intended time period. A zcap still cannot be invoked without being able to use the associated private key material.
### Patches
`@digitalbazaar/zcap` v9.0.1 fixes expiration checking.
### Workarounds
A zcap could be revoked at any time.
### References
https://github.com/digitalbazaar/zcap/pull/82
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/digitalbazaar/zcap/security/advisories/GHSA-hp8h-7x69-4wmv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-31995[ADVISORY]
- https://github.com/digitalbazaar/zcap/pull/82[WEB]
- https://github.com/digitalbazaar/zcap/commit/261eea040109b6e25159c88d8ed49d3c37f8fcfe[WEB]
- https://github.com/digitalbazaar/zcap/commit/55f8549c80124b85dfb0f3dcf83f2c63f42532e5[WEB]
- https://github.com/digitalbazaar/zcap[PACKAGE]