Описание
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.
Ссылки
- Product
- MitigationVendor Advisory
- Third Party Advisory
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.8.7 (исключая)
cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00769
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-798
Связанные уязвимости
CVSS3: 9.8
github
2 месяца назад
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.
EPSS
Процентиль: 53%
0.00769
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-798