PT-2023-21226 · Panindex · Panindex

Cokebeer

·

Publicado

2023-03-13

·

Atualizado

2023-03-17

·

CVE-2023-27583

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PanIndex versions prior to 3.1.3
Description The issue concerns a hard-coded JWT key PanIndex used in PanIndex. This allows an attacker to sign a JWT token and perform actions with admin privileges.
Recommendations For versions prior to 3.1.3, update to version 3.1.3 to resolve the issue. As a temporary workaround for versions prior to 3.1.3, consider changing the JWT key in the source code before compiling the project.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27583
GHSA-82WQ-GMW8-G87V

Produtos afetados

Panindex