Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ggv-wq69-w49q

Опубликовано: 31 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

EPSS

Процентиль: 33%
0.00128
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287
CWE-863

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.

EPSS

Процентиль: 33%
0.00128
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287
CWE-863