CVE-2020-36124: XEE
Published May 7, 2021
·Updated
Pax Technology PAXSTORE v7.0.820200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).
Affected Software
1 affected component
Paxtechnology Paxstore<=7.0.8_20200511171508
Event History
May 7, 2021
CVE Published
via MITRE·10:35 AM
Data Sourced
via MITRE·10:35 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36124?
CVE-2020-36124 is classified as a critical vulnerability due to the potential compromise of JWT private keys.
2
How do I fix CVE-2020-36124?
To fix CVE-2020-36124, upgrade Paxstore to version 7.0.9 or later.
3
What type of vulnerability is CVE-2020-36124?
CVE-2020-36124 is an XML External Entity (XXE) injection vulnerability.
4
Who can exploit CVE-2020-36124?
CVE-2020-36124 can be exploited by an authenticated attacker.
5
What impact does CVE-2020-36124 have on Paxstore?
The impact of CVE-2020-36124 includes the ability to manipulate access tokens and impersonate any user.