sansec/magento2-module-cosmic-sting-jwt
最新稳定版本:0.1.0
Composer 安装命令:
composer require sansec/magento2-module-cosmic-sting-jwt
包简介
无描述信息
README 文档
README
Adobe has released a hotfix for the isolated patch that ensures only the latest encryption key is used for JWTs. If you have applied this hotfix, this module is no longer necessary.
Cosmic Sting JWT
As CosmicSting enables attackers to read any file, attackers can steal Magento's secret encryption key. This encryption key can be used to generate JSON Web Tokens with full administrative API access.
Adobe offers a solution to change the encryption key, but all it does is add an additional key and then attempts to re-encrypt existing secrets with this key. It does nothing to invalidate the old key that is still being referenced in app/etc/env.php.
This module ensures that JWTs are only ever read using the latest encryption key. It is provided as-is and without any warranty or guarantees. Test extensively and use at own risk.
Installation
composer require sansec/magento2-module-cosmic-sting-jwt bin/magento setup:upgrade License
MIT License - Copyright (c) 2024 Sansec
统计信息
- 总下载量: 29.96k
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 17
- 点击次数: 1
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2026-01-04