CVE-2023-31579
Summary
| CVE | CVE-2023-31579 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-02 22:15:00 UTC |
| Updated | 2023-11-09 21:17:00 UTC |
| Description | Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Tangyh |
Lamp-cloud |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Using predictable/constant cryptographic key when creating and verifing Json Web Token. · Issue #183 · dromara/lamp-cloud · GitHub |
MISC |
github.com |
|
| github.com/xubowenW/JWTissues/blob/main/lamp%20issue.md |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995831 Java (Maven) Security Update for top.tangyh.basic:lamp-core (GHSA-xr8c-mq5x-5f56)