Логотип exploitDog
bind:CVE-2024-48952
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-48952

Количество 2

Количество 2

nvd логотип

CVE-2024-48952

больше 1 года назад

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-h4jm-pc24-hx88

больше 1 года назад

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-48952

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-h4jm-pc24-hx88

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.

CVSS3: 6.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу