Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
References
Link Resource
https://balwurk.github.io/CVE-2023-27172/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-20T00:00:00

Updated: 2023-12-20T00:01:55.914186

Reserved: 2023-02-27T00:00:00


Link: CVE-2023-27172

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-20T01:15:07.233

Modified: 2024-01-02T15:00:26.970


Link: CVE-2023-27172

JSON object: View

cve-icon Redhat Information

No data.

CWE