Логотип exploitDog
bind:CVE-2025-51606
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-51606

Количество 2

Количество 2

nvd логотип

CVE-2025-51606

6 месяцев назад

hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". The vulnerability poses a critical security risk in systems where authentication and authorization rely on the integrity of JWTs.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-48cg-9c55-j2q7

6 месяцев назад

hippo4j Includes Hard Coded Secret Key in JWT Creation

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-51606

hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". The vulnerability poses a critical security risk in systems where authentication and authorization rely on the integrity of JWTs.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-48cg-9c55-j2q7

hippo4j Includes Hard Coded Secret Key in JWT Creation

CVSS3: 8.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу