EUVD-2025-25832

The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorizatio ...

Continue Reading
CVE-2025-41702 egOS WebGUI Hard-Coded JWT Secret Enables Authentication Bypass

The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorizatio ...

Continue Reading
CVE-2025-41702 egOS WebGUI Hard-Coded JWT Secret Enables Authentication Bypass

The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorizatio ...

Continue Reading
CVE-2025-30064 Possibility to generate a session for any user via the “ex:action” parameter after obtaining access to the JWT key

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an ...

Continue Reading
CVE-2025-30064 Possibility to generate a session for any user via the “ex:action” parameter after obtaining access to the JWT key

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an ...

Continue Reading
Linux Distros Unpatched Vulnerability : CVE-2019-18848

The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. The json-jwt gem before 1.11.0 for Ruby lacks an element count d ...

Continue Reading
PT-2025-34858 · Unknown · Verifyuserbythrustedservice

Name of the Vulnerable Software and Affected Versions: versions prior to 2.3 Description: An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam fun ...

Continue Reading
Linux Distros Unpatched Vulnerability : CVE-2022-36083

The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. JOSE is JSON Web Almost Everything - JWA, JWS, JWE, JWT, JWK, JW ...

Continue Reading

Back to Main

Subscribe for the latest news: