PT-2023-21226 · Panindex · Panindex

Cokebeer

·

Published

2023-03-13

·

Updated

2023-03-17

·

CVE-2023-27583

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PanIndex versions prior to 3.1.3
Description The issue concerns a hard-coded JWT key PanIndex used in PanIndex. This allows an attacker to sign a JWT token and perform actions with admin privileges.
Recommendations For versions prior to 3.1.3, update to version 3.1.3 to resolve the issue. As a temporary workaround for versions prior to 3.1.3, consider changing the JWT key in the source code before compiling the project.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-27583
GHSA-82WQ-GMW8-G87V

Affected Products

Panindex