Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
References
Link Resource
https://github.com/dromara/lamp-cloud/issues/183 Issue Tracking Patch Vendor Advisory
https://github.com/xubowenW/JWTissues/blob/main/lamp%20issue.md Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-11-02T00:00:00

Updated: 2023-11-02T21:25:06.845490

Reserved: 2023-04-29T00:00:00


Link: CVE-2023-31579

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-02T22:15:08.640

Modified: 2023-11-09T21:17:52.387


Link: CVE-2023-31579

JSON object: View

cve-icon Redhat Information

No data.

CWE