A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.
References
Link Resource
https://github.com/AdaptiveScale/lxdui/pull/353 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-03T01:35:26

Updated: 2021-09-03T01:35:26

Reserved: 2021-09-03T00:00:00


Link: CVE-2021-40494

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-03T02:15:06.467

Modified: 2021-09-10T18:42:55.183


Link: CVE-2021-40494

JSON object: View

cve-icon Redhat Information

No data.

CWE