NocoDB
cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*
- <= 0.301.2
A vulnerability in NocoDB's password reset process prior to version 0.301.3 allowed for the continued use of refresh tokens after a password was changed. The issue arose because the password reset function did not invalidate existing refresh tokens, leaving a window for attackers with stolen tokens to generate valid JSON Web Tokens (JWTs) even after the victim had reset their password.
This vulnerability could lead to unauthorized access, as it allowed attackers to maintain access through stolen refresh tokens even after a password reset.
Users can upgrade to NocoDB version 0.301.3 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.