Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hwr4-f3g6-5mmp

Опубликовано: 25 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

EPSS

Процентиль: 29%
0.00105
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-321

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

EPSS

Процентиль: 29%
0.00105
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-321