sansec/magento2-module-cosmic-sting-jwt 问题修复 & 功能扩展

解决BUG、新增功能、兼容多环境部署,快速响应你的开发需求

邮箱:yvsm@zunyunkeji.com | QQ:316430983 | 微信:yvsm316

sansec/magento2-module-cosmic-sting-jwt

最新稳定版本:0.1.0

Composer 安装命令:

composer require sansec/magento2-module-cosmic-sting-jwt

包简介

无描述信息

README 文档

README

Adobe has released a hotfix for the isolated patch that ensures only the latest encryption key is used for JWTs. If you have applied this hotfix, this module is no longer necessary.

Cosmic Sting JWT

As CosmicSting enables attackers to read any file, attackers can steal Magento's secret encryption key. This encryption key can be used to generate JSON Web Tokens with full administrative API access.

Adobe offers a solution to change the encryption key, but all it does is add an additional key and then attempts to re-encrypt existing secrets with this key. It does nothing to invalidate the old key that is still being referenced in app/etc/env.php.

This module ensures that JWTs are only ever read using the latest encryption key. It is provided as-is and without any warranty or guarantees. Test extensively and use at own risk.

Installation

composer require sansec/magento2-module-cosmic-sting-jwt bin/magento setup:upgrade 

License

MIT License - Copyright (c) 2024 Sansec

统计信息

  • 总下载量: 29.96k
  • 月度下载量: 0
  • 日度下载量: 0
  • 收藏数: 17
  • 点击次数: 1
  • 依赖项目数: 0
  • 推荐数: 0

GitHub 信息

  • Stars: 17
  • Watchers: 4
  • Forks: 2
  • 开发语言: PHP

其他信息

  • 授权协议: MIT
  • 更新时间: 2026-01-04