GHSA-gj7p-595x-qwf5: Data Sharing Framework is Missing Session Timeout for OIDC Sessions
OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired.
References
- dsf.dev/operations/v2.1.0/bpe/oidc.html
- dsf.dev/operations/v2.1.0/fhir/oidc.html
- github.com/advisories/GHSA-gj7p-595x-qwf5
- github.com/datasharingframework/dsf
- github.com/datasharingframework/dsf/commit/7d25feafb83d66cb59985ac88568b67d937b1937
- github.com/datasharingframework/dsf/commit/f4ecb002f7d12642f92da6b79371ed367d0140e7
- github.com/datasharingframework/dsf/security/advisories/GHSA-gj7p-595x-qwf5
Code Behaviors & Features
Detect and mitigate GHSA-gj7p-595x-qwf5 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →