Impact
Casdoor up to and including version 4.4.0 fails to mask the instance-wide private key used for JWT signing in the /api/get-certs and /api/get-cert endpoints. This allows any organization administrator to retrieve the key. With the private key in hand, an attacker can forge JWT tokens that are accepted by the platform as if they were issued by a legitimate user or global administrator, enabling bypass of access controls and unauthorized data access.
Affected Systems
The affected product is Casdoor, a single sign-on solution developed by casbin:casdoor. All installations running version 4.4.0 or earlier are susceptible; newer releases contain the patch that properly obscures the key. No specific subrange beyond the stated major release is provided in the CNA data.
Risk and Exploitability
The CVSS v3.1 score of 9.3 indicates critical severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, but that does not lessen its potential impact. The flaw can be exploited by any authenticated user with organization- administrator privileges who can call the exposed API endpoints, making the attack vector one of legitimate API usage by privileged accounts. An attacker who gains such privileges can capture the key, generate arbitrary JWTs, impersonate users, and potentially control any organization’s resources.
OpenCVE Enrichment