Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8vmp-8f6c-x5hr

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

EPSS

Процентиль: 22%
0.00073
Низкий

7.5 High

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

EPSS

Процентиль: 22%
0.00073
Низкий

7.5 High

CVSS3

Дефекты

CWE-798