CVE-2023-33236: MXsecurity Hardcoded Credential Vulnerability
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MXsecurity Seriesto a version that resolves this vulnerability.Fixed in 1.0.1
Event History
Frequently Asked Questions
What is CVE-2023-33236?
CVE-2023-33236 is a hardcoded credential vulnerability in MXsecurity version 1.0 that allows the crafting of arbitrary JWT tokens and bypassing of authentication for web-based APIs.
What is the severity of CVE-2023-33236?
The severity of CVE-2023-33236 is critical with a CVSS score of 9.8.
How can MXsecurity version 1.0 be exploited?
MXsecurity version 1.0 can be exploited by crafting arbitrary JWT tokens to bypass authentication for web-based APIs.
Is there a fix available for CVE-2023-33236?
Please check the provided reference link for information on available fixes for CVE-2023-33236.
What is the CWE number for CVE-2023-33236?
CVE-2023-33236 is associated with CWE-798 (Use of Hard-coded Credentials).