ZeroHour
Exploit-DBpublished ()ingested

[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak

lowExploit / PoCimportance 21
AI summary · glm-5.3-flash

A public exploit exposes JWT signing key leakage in backup software Duplicati 2.2.0.3, risking session forgery.

Exploit-DB published exploit #52646 for Duplicati 2.2.0.3, a backup application. The issue leaks the JWT signing key, which could let an attacker forge authentication tokens. The disclosure does not report any exploitation in the wild.

  • Exploit-DB entry 52646 targets Duplicati 2.2.0.3
  • JWT signing key leak enables potential token forgery
  • No confirmed in-the-wild exploitation noted
VendorsDuplicati
ProductsDuplicati
Full article

Duplicati 2.2.0.3 - JWT Signing Key Leak

This source does not provide full text. Read it at exploit-db.com.