GHSA-h5fq-653g-gxrm: ots has a negative expire override that can bypass its secret retention policy
The /api/create endpoint accepted negative expire query values. For the memory storage backend, negative values were passed to secret creation as a negative duration and treated as no expiry, allowing callers to create secrets that persisted longer than intended.
References
Code Behaviors & Features
Detect and mitigate GHSA-h5fq-653g-gxrm with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →