Product
high
advisory
Ech0 'Never Expire' Access Tokens Cannot Be Revoked
2 rules 1 TTPEch0's access tokens with the 'never expire' option cannot be revoked through logout or deletion, leading to persistent access until the JWT secret is rotated instance-wide.
Ech0
credential-access
token-revocation
web-application
2r
1t
high
advisory
Ech0 Scoped Admin Access Token Bypass
2 rules 1 TTPEch0 scoped access tokens do not reliably enforce least privilege, leading to privilege escalation and data exfiltration by allowing low-scope admin tokens to access broader admin functionality, including backup exports.
Ech0
privilege-escalation
data-exfiltration
access-token
2r
1t