vendor:
https://github.com/ever-co/ever-gauzy/releases/tag/v0.281.9
by:
nu11secur1ty
7.5
CVSS
HIGH
JWT weak HMAC secret
CWE
Product Name: https://github.com/ever-co/ever-gauzy/releases/tag/v0.281.9
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2023
ever gauzy v0.281.9 – JWT weak HMAC secret
It was detected a JWT signed using a well-known HMAC secret key. The key used which was found was a secret Key. The user can find a secret key authentication while sending normal post requests. After he found the Authorization: Bearer key he can use it to authenticate and he can be sending a very malicious POST request, it depends on the scenario.