QID 995831
Date Published: 2023-11-06
QID 995831: Java (Maven) Security Update for top.tangyh.basic:lamp-core (GHSA-xr8c-mq5x-5f56)
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xr8c-mq5x-5f56 for updates and patch information.
Vendor References
- GHSA-xr8c-mq5x-5f56 -
github.com/advisories/GHSA-xr8c-mq5x-5f56
CVEs related to QID 995831
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xr8c-mq5x-5f56 | top.tangyh.basic:lamp-core |
|