PT-2024-13391 · Npm · @Evershop/Evershop

Published

2024-01-12

·

Updated

2024-08-30

·

CVE-2023-46943

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @evershop/evershop versions prior to 1.0.0-rc.8
Description An issue was discovered in NPM's package @evershop/evershop where the HMAC secret used for generating tokens is hardcoded as "secret". This poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
Recommendations For versions prior to 1.0.0-rc.8, update to version 1.0.0-rc.8 or later to resolve the issue. As a temporary workaround, consider regenerating the HMAC secret with a secure, randomly generated value to prevent attackers from creating valid JSON Web Tokens (JWTs).

Fix

Improper Access Control

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2023-46943
GHSA-32R3-57HP-CGFW

Affected Products

@Evershop/Evershop