ZeroHour

CVE-2023-36649

PoC
CVSS 3.1
9.1 critical
EPSS
<1%p57
Published
()
Modified
Description

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

Vendors
prolion
Products
cryptospike
Weakness
CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.