ZeroHour

CVE-2021-27884

CVSS 3.1
5.1 medium
EPSS
<1%p27
Published
()
Modified
Description

Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used.

Vendors
ymfe
Products
yapi
Weakness
CWE-330
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.