Логотип exploitDog
bind:CVE-2023-48396
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-48396

Количество 2

Количество 2

nvd логотип

CVE-2023-48396

больше 1 года назад

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token. This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version 1.0.1, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-cp2c-x2pc-fph7

больше 1 года назад

Apache SeaTunnel Web Authentication vulnerability

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-48396

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token. This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version 1.0.1, which fixes the issue.

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-cp2c-x2pc-fph7

Apache SeaTunnel Web Authentication vulnerability

CVSS3: 8.2
0%
Низкий
больше 1 года назад

Уязвимостей на страницу