GHSA-xcp4-62vj-cq3r
CRITICALCVE-2024-34706When opening a form in Valtimo, the access token (JWT) of the user is exposed to api.form.io via the the x-jwt-token header. An attacker can retrieve personal information from this token, or use it to execute requests to the Valtimo REST API on behalf of the logged-in user.
- Affected
- >= 11.0.0, < 11.1.6, < 10.8.4, >= 11.2.0, < 11.2.2
- Fixed in
- 11.1.6
- Weakness
- CWE-532
- Published
- 2024-05-13
- Source
- github