Brocade ASC-Gateway OVA JSON Web Token Exposure Vulnerability
Vulnerability
A vulnerability exists in Brocade ASC-Gateway OVA versions prior to 3.3.0, where JSON Web Tokens (JWT) are logged in plaintext in log files. This exposure allows an attacker with access to the logs to retrieve unencrypted tokens, potentially leading to unauthorized access, session hijacking, and information disclosure.
Impact
The vulnerability could be exploited to access sensitive information contained in the JSON Web Tokens, such as user credentials or session identifiers, which could then be used to impersonate a user or gain unauthorized access to resources.
Remediation
Users are advised to upgrade to Brocade ASC-Gateway version 3.3.0 or later, where this vulnerability has been addressed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
