DataEase
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*, +1 more
- <= 2.10.8
A vulnerability allowing JWT token forgery has been identified in DataEase versions prior to 2.10.10. The issue arises because secret verification is not properly enforced, enabling users to create tokens without valid secrets. This flaw has been addressed in version 2.10.10.
Exploitation of this vulnerability allows for unauthorized JWT token creation, which could be used to impersonate users or gain unauthorized access to resources.
To reproduce this vulnerability, send a request including a JWT token in the X-DE-TOKEN header. The token can be forged using any secret, as the application does not properly validate the token's authenticity before processing the request.
Users are advised to upgrade to DataEase version 2.10.10 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.