Логотип exploitDog
bind:CVE-2025-13877
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-13877

Количество 2

Количество 2

nvd логотип

CVE-2025-13877

2 месяца назад

A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cryptographic key . The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-mv7p-34fv-4874

2 месяца назад

Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-13877

A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the file nocobase\packages\core\auth\src\base\jwt-service.ts of the component JWT Service. The manipulation of the argument API_KEY results in use of hard-coded cryptographic key . The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.6
0%
Низкий
2 месяца назад
github логотип
GHSA-mv7p-34fv-4874

Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments

0%
Низкий
2 месяца назад

Уязвимостей на страницу