Description
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6585 | Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access. |
Github GHSA |
GHSA-mj5w-w588-j6xg | Use of Hard-coded Credentials in AgileConfig.Client |
References
| Link | Providers |
|---|---|
| https://github.com/dotnetcore/AgileConfig/issues/91 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T09:36:44.403Z
Reserved: 2022-07-11T00:00:00.000Z
Link: CVE-2022-35540
No data.
Status : Modified
Published: 2022-08-18T23:15:08.293
Modified: 2024-11-21T07:11:19.283
Link: CVE-2022-35540
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA