An issue was discovered in Object First 1.0.7.712. The...
Critical severity
Unreviewed
Published
Nov 7, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Nov 7, 2022
Published to the GitHub Advisory Database
Nov 7, 2022
Last updated
Jan 29, 2023
An issue was discovered in Object First 1.0.7.712. The authorization service has a flow that allows getting access to the Web UI without knowing credentials. For signing, the JWT token uses a secret key that is generated through a function that doesn't produce cryptographically strong sequences. An attacker can predict these sequences and generate a JWT token. As a result, an attacker can get access to the Web UI. This is fixed in 1.0.13.1611.
References