CVE-2024-48952 - CERT CVE
ID CVE-2024-48952
Sažetak An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.
Reference
CVSS
Base: 6.4
Impact: 4.7
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 08-11-2024 - 19:01
Objavljeno 07-11-2024 - 17:15