Логотип exploitDog
bind:CVE-2023-36647
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-36647

Количество 2

Количество 2

nvd логотип

CVE-2023-36647

около 2 лет назад

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8vmp-8f6c-x5hr

около 2 лет назад

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-36647

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-8vmp-8f6c-x5hr

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

CVSS3: 7.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу