PT-2024-22328 · Unknown · Yourspotify

Ragingcactus

·

Published

2024-03-13

·

Updated

2024-03-14

·

CVE-2024-28194

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YourSpotify versions prior to 1.8.0
Description The issue concerns the use of a hardcoded JSON Web Token (JWT) secret in authentication tokens. This allows attackers to forge valid authentication tokens for any user, effectively bypassing authentication and potentially authenticating as admin users.
Recommendations For versions prior to 1.8.0, upgrade to version 1.8.0 to address the issue. As a temporary workaround, consider restricting access to sensitive features until the upgrade is applied.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-28194
GHSA-GVCR-G265-J827

Affected Products

Yourspotify