[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
A public exploit exposes JWT signing key leakage in backup software Duplicati 2.2.0.3, risking session forgery.
Exploit-DB published exploit #52646 for Duplicati 2.2.0.3, a backup application. The issue leaks the JWT signing key, which could let an attacker forge authentication tokens. The disclosure does not report any exploitation in the wild.
21