A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36647 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-12T00:00:00

Updated: 2023-12-12T00:06:33.804327

Reserved: 2023-06-25T00:00:00


Link: CVE-2023-36647

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-12T01:15:10.010

Modified: 2023-12-14T00:03:46.357


Link: CVE-2023-36647

JSON object: View

cve-icon Redhat Information

No data.

CWE