Логотип exploitDog
bind:CVE-2025-43866
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43866

Количество 2

Количество 2

nvd логотип

CVE-2025-43866

8 месяцев назад

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent. This vulnerability is fixed in 4.11.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-m3mq-f375-5vgh

8 месяцев назад

Vantage6 Server JWT secret not cryptographically secure

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43866

vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictable to some extent. This vulnerability is fixed in 4.11.0.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-m3mq-f375-5vgh

Vantage6 Server JWT secret not cryptographically secure

0%
Низкий
8 месяцев назад

Уязвимостей на страницу