GHSA-xr8c-mq5x-5f56
HIGHCVE-2023-31579Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
- Affected
- < 3.8.1
- Fixed in
- 3.8.1
- Weakness
- CWE-798
- Published
- 2023-11-03
- Source
- github