Description
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not revoke existing refresh tokens, allowing an attacker with a previously stolen refresh token to continue minting valid JWTs after the victim resets their password. This issue has been patched in version 0.301.3.
Problem types
CWE-613: Insufficient Session Expiration
Product status
References
github.com/...nocodb/security/advisories/GHSA-x4vh-j75g-268g
github.com/nocodb/nocodb/releases/tag/0.301.3