Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-03-01T23:00:51

Updated: 2021-03-01T23:00:51

Reserved: 2021-03-01T00:00:00


Link: CVE-2021-27884

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-03-01T23:15:13.267

Modified: 2021-03-08T16:24:18.490


Link: CVE-2021-27884

JSON object: View

cve-icon Redhat Information

No data.

CWE