PT-2026-2356 · Cobbr+1 · Covenant
Coastal
·
Publicado
2026-01-13
·
Atualizado
2026-01-29
·
CVE-2020-36911
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Covenant versions 0.1.3 through 0.5
Description
The software contains a remote code execution issue that allows attackers to create malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system. The vulnerability involves crafting JWT tokens to gain unauthorized access and execute code.
Recommendations
Update to a newer version that addresses this issue.
Exploit
Correção
RCE
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Covenant