CVE-2023-33371

Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication. ...

Continue Reading
Exploit for CVE-2021-44910

# CVE-2021-44910-SpringBlade漏洞检测工具 在21年,SpringBlade框架曾发现一个JW...Read More ...

Continue Reading
Weak JWT Secrets

github.com/IceWhaleTech/CasaOS is vulnerable to Weak JWT Secrets. The vulnerability exists because the `InitV1Router` function of `v1.go` and `InitV2Router` function of `v2.go` does not properly valid ...

Continue Reading
CVE-2023-35134

Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.Read More ...

Continue Reading
CVE-2023-34429

Weintek Weincloud v0.13.6 could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.Read More ...

Continue Reading
​Weintek Weincloud

## 1. EXECUTIVE SUMMARY * **​CVSS v3 9.8** * **​ATTENTION: **Exploitable remotely/low attack complexity * **​Vendor: **Weintek * **​Equipment: **Weincloud * **​Vulne ...

Continue Reading
CasaOS contains weak JWT secrets

### Impact Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. ### Patches The prob ...

Continue Reading
Amazon Linux 2 : ecs-service-connect-agent (ALASECS-2023-003)

The version of ecs-service-connect-agent installed on the remote host is prior to v1.25.4.0-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2ECS-2023-003 advisory. ...

Continue Reading

Back to Main

Subscribe for the latest news: