Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhgj-gg86-h6q2

Опубликовано: 27 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8

Описание

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" parameter in the VerifyUserByThrustedService function to generate a session for any user.

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" parameter in the VerifyUserByThrustedService function to generate a session for any user.

EPSS

Процентиль: 1%
0.00009
Низкий

8.8 High

CVSS4

Дефекты

CWE-347

Связанные уязвимости

nvd
6 месяцев назад

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" parameter in the VerifyUserByThrustedService function to generate a session for any user.

EPSS

Процентиль: 1%
0.00009
Низкий

8.8 High

CVSS4

Дефекты

CWE-347