CVE-2024-57432: High severity macrozheng mall-tiny vulnerability
macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it is possible to forge the JWT of any user to achieve authentication bypass.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57432?
CVE-2024-57432 has a high severity due to the potential for user impersonation through forged JWTs.
How do I fix CVE-2024-57432?
To fix CVE-2024-57432, update the application to change JWT signing keys regularly and avoid hardcoding them.
What impact does CVE-2024-57432 have on user data security?
CVE-2024-57432 allows attackers to forge JWTs, potentially compromising user data and access controls.
Which versions of macrozheng mall-tiny are affected by CVE-2024-57432?
CVE-2024-57432 affects macrozheng mall-tiny version 1.0.1 and potentially other versions that inherit this vulnerability.
Is CVE-2024-57432 easy to exploit?
CVE-2024-57432 can be easily exploited by attackers with access to the application's JWT, allowing them to impersonate any user.