First published: Tue Sep 24 2024(Updated: )
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iceCMS | <3.4.7 | |
iCMS | <3.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46612 has been classified as a high severity vulnerability due to the potential for authentication forgery.
To mitigate CVE-2024-46612, update IceCMS to version 3.4.8 or later, which removes the hardcoded JWT key.
CVE-2024-46612 can allow attackers to bypass authentication mechanisms, potentially leading to unauthorized access to sensitive data.
CVE-2024-46612 affects IceCMS versions 3.4.7 and earlier.
If upgrading is not possible, consider implementing additional security measures, such as strict API access controls, until the application can be updated.