. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15075 | A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Apr 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastcms Project
Fastcms Project fastcms |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:fastcms_project:fastcms:0.1.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Fastcms Project
Fastcms Project fastcms |
Thu, 03 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. | |
| Title | FastCMS JWT hard-coded key | |
| Weaknesses | CWE-320 CWE-321 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-03T20:35:32.064Z
Reserved: 2025-04-03T08:33:56.483Z
Link: CVE-2025-3177
Updated: 2025-04-03T20:35:23.378Z
Status : Analyzed
Published: 2025-04-03T20:15:27.507
Modified: 2025-04-08T19:40:08.587
Link: CVE-2025-3177
No data.
OpenCVE Enrichment
No data.
EUVD