AdaptiveScale LXDUI Hardcoded JWT Secret Key
Critical severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Sep 3, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Apr 22, 2024
Last updated
Sep 30, 2024
A Hardcoded JWT Secret Key in
__metadata__.py
metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.References