Impact
Crawlab versions up to 0.6.3 expose a hard‑coded HMAC‑SHA256 secret used to sign JSON Web Tokens. Because the secret cannot be overridden through configuration or environment variables, an unauthenticated attacker can generate a token that appears to be issued by an administrator. With such a forged token the attacker can authenticate to the application’s administrative APIs and issue commands that are executed on worker nodes, effectively gaining full control over the system. The vulnerability is classified as CWE‑321, reflecting improper storage of cryptographic key material.
Affected Systems
The affected product is Crawlab provided by the crawlab-team. All releases with a major version of 0.6.x up to 0.6.3 are impacted. No specific patch version is listed in the CNA data, so any installation of Crawlab 0.6 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 9.3 indicates high exploitation risk. EPSS data is not available, so the prevalence of exploitation in the wild is uncertain. The vulnerability is not listed in the CISA KEV catalog, but because adversaries can obscure their identity simply by forging a token, the risk remains significant. The attack requires no privileged network access; simply obtaining a valid JWT by computing the hash with the known secret allows the attacker to access administrative functionality. The vulnerability is thus remotely exploitable with minimal effort once the application is publicly reachable.
OpenCVE Enrichment