Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.veeam.com/kb4585 |
|
History
Thu, 27 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veeam
Veeam recovery Orchestrator |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:veeam:recovery_orchestrator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Veeam
Veeam recovery Orchestrator |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-03-27T21:09:44.177Z
Reserved: 2024-03-21T01:04:07.090Z
Link: CVE-2024-29855
Updated: 2024-08-02T01:17:58.173Z
Status : Analyzed
Published: 2024-06-11T04:15:12.953
Modified: 2025-07-14T20:21:24.087
Link: CVE-2024-29855
No data.
OpenCVE Enrichment
No data.
Weaknesses