Junglewise Threat Intelligence

CVE-2024-31995: Digital Bazaar zcap incomplete expiration checks in capability chains

CVE-2024-31995 · Severity: low · CVSS 3.1 · Published 2024-04-10

Vendors: Digital Bazaar, npm.

Executive brief

Digital Bazaar's zcap library manages cryptographic capability tokens used for delegated authorization in decentralized systems. The library failed to properly validate expiration dates on delegated capabilities, allowing attackers with access to private key material to use expired authorization tokens beyond their intended time window. This could enable unauthorized actions if a capability is delegated but later expires or if time-based access controls are relied upon for security.

Technical details

The vulnerability is an improper input validation (CWE-20) and insufficient session expiration (CWE-613) flaw in the zcap library's capability chain handling. When a capability is invoked with a chain depth of 2 (delegated directly from the root capability), the expires property is not properly validated against the current date or supplied date parameter. An attacker who possesses the associated private key material can invoke expired capabilities outside the originally intended time period. The flaw requires the attacker to already have access to the private key, limiting the attack surface. A fix was released in version 9.0.1.

Affected products

  • Digital Bazaar zcap before 9.0.1

Timeline

  • 2024-04-10: disclosed
  • 2024-04-10: patched: Fixed in v9.0.1

References