Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh83-9fpx-6f4r

Опубликовано: 19 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

EPSS

Процентиль: 14%
0.00044
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

EPSS

Процентиль: 14%
0.00044
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-347