Описание
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
Ссылки
EPSS
Процентиль: 12%
0.0021
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 9.6
github
5 дней назад
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.
EPSS
Процентиль: 12%
0.0021
Низкий
9.6 Critical
CVSS3
Дефекты
CWE-863