Home
MEDIUM: 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:NDefault status
unaffected
15 (custom) before 17.1
affected
Description
In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.
Problem types
CWE-420 Unprotected Alternate Channel
Product status
15 (custom) before 17.1
References
docs.oxide.computer/security/advisories/20251117-1
github.com/oxidecomputer/omicron/compare/01bb875...ec069f0