KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys

### Summary The jwt authentication function of kubepi Read More ...

Continue Reading
JwtSigKey hardcoded causes the k8s cluster to take over

# Description The jwt authentication function of kubepi Read More ...

Continue Reading
CVE-2023-22463

KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker ...

Continue Reading
robbert229/jwt’s token validation methods vulnerable to a timing side-channel during HMAC comparison

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine th ...

Continue Reading
robbert229/jwt’s token validation methods vulnerable to a timing side-channel during HMAC comparison

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine th ...

Continue Reading
CVE-2015-10004

This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will b ...

Continue Reading
Linktree: Account takeover – improper validation of jwt signature (with regards to experiation date claim)

Some backend services did not properly validate JWTs. As a result JWT validation could be bypassed by setting the expiration date claim to a unix timestamp in the past, and abusing this for account ta ...

Continue Reading
CVE-2022-39304

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installa ...

Continue Reading

Back to Main

Subscribe for the latest news: