Xpand IT Write-back Manager v2.3.1 uses weak secret keys...
Critical severity
Unreviewed
Published
Dec 20, 2023
to the GitHub Advisory Database
•
Updated Jan 2, 2024
Description
Published by the National Vulnerability Database
Dec 20, 2023
Published to the GitHub Advisory Database
Dec 20, 2023
Last updated
Jan 2, 2024
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.
References