Description
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs out. As of time of publication, no known patches exist.
Problem types
CWE-305: Authentication Bypass by Primary Weakness
CWE-385: Covert Timing Channel
CWE-613: Insufficient Session Expiration
Product status
References
github.com/...rowser/security/advisories/GHSA-7xwp-2cpp-p8r7
github.com/...rowser/security/advisories/GHSA-7xwp-2cpp-p8r7
github.com/filebrowser/filebrowser/issues/5216