Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-53951

Опубликовано: 19 дек. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

EPSS

Процентиль: 15%
0.00048
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
github
около 2 месяцев назад

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

EPSS

Процентиль: 15%
0.00048
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347