Seinwacht
Terug naar meldingen
laagFortinet PSIRTAdvisory

JWT used for authentication in web GUI signed with static key

Actief misbruik
Niet bevestigd
Hoogste CVSS
—
Kans op misbruik (EPSS)
—
Prioriteit
0 van 100

Citaat uit de bron

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication… …

Lees de volledige melding bij Fortinet PSIRTBron: Fortinet PSIRT, © Fortinet.

JWT used for authentication in web GUI signed with static key | Seinwacht