Headline
GHSA-x72p-g37q-4xr9: SFTPGo's JWT implmentation lacks certain security measures
In SFTPGo 2.6.2, the JWT implementation lacks certain security measures, such as using JWT ID (JTI) claims, nonces, and proper expiration and invalidation mechanisms.
SFTPGo’s JWT implmentation lacks certain security measures
Moderate severity GitHub Reviewed Published Jul 22, 2024 to the GitHub Advisory Database • Updated Jul 22, 2024