Impact
File Browser versions 2.50.0 through 2.63.21 do not enforce JWT expiration when proxy authentication is configured with a non‑default logout page. As a result, an attacker who already possesses a valid token can continue to use protected routes and administrative endpoints indefinitely, and can even exchange expired tokens for new ones through the renewal endpoint. The weakness, identified as CWE‑613, enables persistent privileged access that can compromise confidentiality and integrity of the system.
Affected Systems
The vulnerability affects the File Browser product from the filebrowser vendor. All releases between 2.50.0 and 2.63.21 are impacted. Administrators should verify the version of their deployment and identify any instance that falls within this range so that a patch or mitigation can be applied.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity vulnerability, and although the EPSS score is not available, the lack of an enforceable expiration check makes exploitation straightforward for anyone who can obtain an initial valid token. Based on the description, it is inferred that the attack can be performed remotely through the web interface using a previously valid token, and the renewal endpoint provides a convenient way to re‑authenticate. Because the issue is not listed in CISA KEV, no “known exploited” indicator is currently present, but the high severity and direct bypass of authentication mechanisms warrant immediate attention.
OpenCVE Enrichment